CWE-266
AllowedIncorrect Privilege Assignment
Abstraction: Base · Status: Draft
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
2329 vulnerabilities reference this CWE, most recent first.
CVE-2026-90812 (GCVE-0-2026-90812)
Vulnerability from cvelistv5 – Published: 2026-09-14 19:00 – Updated: 2026-09-16 16:08- CWE-266 - Incorrect Privilege Assignment
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403314 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403314/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90812 | third-party-advisory |
| https://vuldb.com/submit/922878 | third-party-advisory |
| https://github.com/cosmicstack-labs/mercury-agent… | exploitissue-tracking |
| https://github.com/cosmicstack-labs/mercury-agent/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| cosmicstack-labs | mercury-agent |
Affected:
1.0
Affected: 1.1 Affected: 1.2.0 cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90812",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T16:08:47.338973Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T16:08:58.364Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*"
],
"modules": [
"Shell Command Permission"
],
"product": "mercury-agent",
"vendor": "cosmicstack-labs",
"versions": [
{
"status": "affected",
"version": "1.0"
},
{
"status": "affected",
"version": "1.1"
},
{
"status": "affected",
"version": "1.2.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Eric-a (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T19:00:09.686Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403314 | cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403314"
},
{
"name": "VDB-403314 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403314/cti"
},
{
"name": "CVE-2026-90812 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90812"
},
{
"name": "Submit #922878 | CosmicStack Labs Mercury Agent (@cosmicstack/mercury-agent) \u003c= 1.2.0 Incorrect Privilege Assignment (CWE-266) / Exposure of Sensitive Information (CWE-200)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/922878"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/cosmicstack-labs/mercury-agent/issues/80"
},
{
"tags": [
"product"
],
"url": "https://github.com/cosmicstack-labs/mercury-agent/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-13T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-13T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-13T18:35:09.000Z",
"value": "VulDB entry last update"
}
],
"title": "cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90812",
"datePublished": "2026-09-14T19:00:09.686Z",
"dateReserved": "2026-09-13T16:29:48.552Z",
"dateUpdated": "2026-09-16T16:08:58.364Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90810 (GCVE-0-2026-90810)
Vulnerability from cvelistv5 – Published: 2026-09-14 18:30 – Updated: 2026-09-15 14:54| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403312 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403312/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90810 | third-party-advisory |
| https://vuldb.com/submit/922876 | third-party-advisory |
| https://github.com/cosmicstack-labs/mercury-agent… | exploitissue-tracking |
| https://github.com/cosmicstack-labs/mercury-agent/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| cosmicstack-labs | mercury-agent |
Affected:
1.1.0
Affected: 1.1.1 Affected: 1.1.2 Affected: 1.1.3 Affected: 1.1.4 Affected: 1.1.5 Affected: 1.1.6 Affected: 1.1.7 Affected: 1.1.8 Affected: 1.1.9 Affected: 1.1.10 Affected: 1.1.11 Affected: 1.1.12 Affected: 1.1.13 cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90810",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T14:54:18.887653Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T14:54:24.698Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/922876"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*"
],
"modules": [
"Shell Command Permission Check"
],
"product": "mercury-agent",
"vendor": "cosmicstack-labs",
"versions": [
{
"status": "affected",
"version": "1.1.0"
},
{
"status": "affected",
"version": "1.1.1"
},
{
"status": "affected",
"version": "1.1.2"
},
{
"status": "affected",
"version": "1.1.3"
},
{
"status": "affected",
"version": "1.1.4"
},
{
"status": "affected",
"version": "1.1.5"
},
{
"status": "affected",
"version": "1.1.6"
},
{
"status": "affected",
"version": "1.1.7"
},
{
"status": "affected",
"version": "1.1.8"
},
{
"status": "affected",
"version": "1.1.9"
},
{
"status": "affected",
"version": "1.1.10"
},
{
"status": "affected",
"version": "1.1.11"
},
{
"status": "affected",
"version": "1.1.12"
},
{
"status": "affected",
"version": "1.1.13"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Eric-a (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T18:30:08.691Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403312 | cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403312"
},
{
"name": "VDB-403312 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403312/cti"
},
{
"name": "CVE-2026-90810 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90810"
},
{
"name": "Submit #922876 | cosmicstack-labs mercury-agent \u003c= 1.1.13 Improper Authorization (CWE-285)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/922876"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/cosmicstack-labs/mercury-agent/issues/101"
},
{
"tags": [
"product"
],
"url": "https://github.com/cosmicstack-labs/mercury-agent/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-13T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-13T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-13T18:35:00.000Z",
"value": "VulDB entry last update"
}
],
"title": "cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90810",
"datePublished": "2026-09-14T18:30:08.691Z",
"dateReserved": "2026-09-13T16:29:41.352Z",
"dateUpdated": "2026-09-15T14:54:24.698Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90787 (GCVE-0-2026-90787)
Vulnerability from cvelistv5 – Published: 2026-09-14 13:45 – Updated: 2026-09-14 15:37| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403293 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403293/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90787 | third-party-advisory |
| https://vuldb.com/submit/919259 | third-party-advisory |
| https://github.com/Soarkey/StudentManagement/issues/35 | exploitissue-tracking |
| https://github.com/Soarkey/StudentManagement/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| Soarkey | StudentManagement |
Affected:
e08f7f1d5015af407aa4cca0ada3dea189b4937e
cpe:2.3:a:soarkey:studentmanagement:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90787",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:37:34.962210Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:37:50.837Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:soarkey:studentmanagement:*:*:*:*:*:*:*:*"
],
"modules": [
"Registration Workflow"
],
"product": "StudentManagement",
"vendor": "Soarkey",
"versions": [
{
"status": "affected",
"version": "e08f7f1d5015af407aa4cca0ada3dea189b4937e"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jacinta (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T13:45:07.810Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403293 | Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403293"
},
{
"name": "VDB-403293 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403293/cti"
},
{
"name": "CVE-2026-90787 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90787"
},
{
"name": "Submit #919259 | Soarkey StudentManagement e08f7f1d5015af407aa4cca0ada3dea189b4937e Use of Client-Side Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919259"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/Soarkey/StudentManagement/issues/35"
},
{
"tags": [
"product"
],
"url": "https://github.com/Soarkey/StudentManagement/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-13T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-13T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-13T15:08:34.000Z",
"value": "VulDB entry last update"
}
],
"title": "Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90787",
"datePublished": "2026-09-14T13:45:07.810Z",
"dateReserved": "2026-09-13T13:03:28.468Z",
"dateUpdated": "2026-09-14T15:37:50.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90566 (GCVE-0-2026-90566)
Vulnerability from cvelistv5 – Published: 2026-09-13 15:45 – Updated: 2026-09-14 15:27| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403151 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403151/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90566 | third-party-advisory |
| https://vuldb.com/submit/912565 | third-party-advisory |
| http://github.com/Rizwan17/inventory-management-s… | exploitissue-tracking |
| Vendor | Product | Version | |
|---|---|---|---|
| Rizwan17 | inventory-management-system |
Affected:
bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90566",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:26:54.799481Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:27:09.390Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*"
],
"modules": [
"Registration Handler"
],
"product": "inventory-management-system",
"vendor": "Rizwan17",
"versions": [
{
"status": "affected",
"version": "bfe78a330d01bb26b9daec5dc9ecd5c77900e03f"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sybululu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T15:45:07.706Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403151 | Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403151"
},
{
"name": "VDB-403151 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403151/cti"
},
{
"name": "CVE-2026-90566 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90566"
},
{
"name": "Submit #912565 | Rizwan17 inventory-management-system bfe78a330d01bb26b9daec5dc9ecd5c77900e03f Improper Authorization",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/912565"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "http://github.com/Rizwan17/inventory-management-system/issues/16"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T17:56:56.000Z",
"value": "VulDB entry last update"
}
],
"title": "Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90566",
"datePublished": "2026-09-13T15:45:07.706Z",
"dateReserved": "2026-09-12T15:51:47.111Z",
"dateUpdated": "2026-09-14T15:27:09.390Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90565 (GCVE-0-2026-90565)
Vulnerability from cvelistv5 – Published: 2026-09-13 15:30 – Updated: 2026-09-16 14:11| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403150 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403150/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90565 | third-party-advisory |
| https://vuldb.com/submit/912564 | third-party-advisory |
| https://github.com/Rizwan17/inventory-management-… | exploitissue-tracking |
| https://github.com/Rizwan17/inventory-management-… | product |
| Vendor | Product | Version | |
|---|---|---|---|
| Rizwan17 | inventory-management-system |
Affected:
bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90565",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:11:06.504470Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:11:38.592Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*"
],
"product": "inventory-management-system",
"vendor": "Rizwan17",
"versions": [
{
"status": "affected",
"version": "bfe78a330d01bb26b9daec5dc9ecd5c77900e03f"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sybululu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T15:30:10.041Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403150 | Rizwan17 inventory-management-system dashboard.php access control",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403150"
},
{
"name": "VDB-403150 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403150/cti"
},
{
"name": "CVE-2026-90565 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90565"
},
{
"name": "Submit #912564 | Rizwan17 inventory-management-system bfe78a330d01bb26b9daec5dc9ecd5c77900e03f Improper Access Controls",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/912564"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/Rizwan17/inventory-management-system/issues/15"
},
{
"tags": [
"product"
],
"url": "https://github.com/Rizwan17/inventory-management-system/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T17:56:52.000Z",
"value": "VulDB entry last update"
}
],
"title": "Rizwan17 inventory-management-system dashboard.php access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90565",
"datePublished": "2026-09-13T15:30:10.041Z",
"dateReserved": "2026-09-12T15:51:43.807Z",
"dateUpdated": "2026-09-16T14:11:38.592Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90523 (GCVE-0-2026-90523)
Vulnerability from cvelistv5 – Published: 2026-09-13 13:15 – Updated: 2026-09-14 15:29 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403113 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403113/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90523 | third-party-advisory |
| https://vuldb.com/submit/912244 | third-party-advisory |
| https://github.com/jaychouchannel/Tourism-Managem… | exploitissue-tracking |
| https://github.com/jaychouchannel/Tourism-Managem… | patch |
| https://github.com/jaychouchannel/Tourism-Managem… | product |
| Vendor | Product | Version | |
|---|---|---|---|
| jaychouchannel | Tourism-Management-System |
Affected:
229956e20dbd4a80eeff14535e44d3099502af09
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90523",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:28:50.579451Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:29:01.108Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*"
],
"modules": [
"User Register Endpoint"
],
"product": "Tourism-Management-System",
"vendor": "jaychouchannel",
"versions": [
{
"status": "affected",
"version": "229956e20dbd4a80eeff14535e44d3099502af09"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Chenshiyi (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T13:15:18.551Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403113 | jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403113"
},
{
"name": "VDB-403113 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403113/cti"
},
{
"name": "CVE-2026-90523 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90523"
},
{
"name": "Submit #912244 | **Vendor:** jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Incorrect Privilege Assignment",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/912244"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/issues/10"
},
{
"tags": [
"patch"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/commit/84d8ec384f669df3985293dab293bb7b477efa64"
},
{
"tags": [
"product"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T13:00:22.000Z",
"value": "VulDB entry last update"
}
],
"title": "jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90523",
"datePublished": "2026-09-13T13:15:18.551Z",
"dateReserved": "2026-09-12T10:55:01.371Z",
"dateUpdated": "2026-09-14T15:29:01.108Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90520 (GCVE-0-2026-90520)
Vulnerability from cvelistv5 – Published: 2026-09-13 12:30 – Updated: 2026-09-20 00:35 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403110 | vdb-entry |
| https://vuldb.com/vuln/403110/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90520 | third-party-advisory |
| https://vuldb.com/submit/912234 | third-party-advisory |
| https://github.com/jaychouchannel/Tourism-Managem… | exploitissue-tracking |
| https://github.com/jaychouchannel/Tourism-Managem… | patch |
| https://github.com/jaychouchannel/Tourism-Managem… | product |
| Vendor | Product | Version | |
|---|---|---|---|
| jaychouchannel | Tourism-Management-System |
Affected:
84d8ec384f669df3985293dab293bb7b477efa64
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90520",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-20T00:11:55.456634Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T00:35:31.442Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*"
],
"modules": [
"Authorization Interceptor"
],
"product": "Tourism-Management-System",
"vendor": "jaychouchannel",
"versions": [
{
"status": "affected",
"version": "84d8ec384f669df3985293dab293bb7b477efa64"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Djie (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T12:30:10.123Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403110 | jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/403110"
},
{
"name": "VDB-403110 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403110/cti"
},
{
"name": "CVE-2026-90520 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90520"
},
{
"name": "Submit #912234 | jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Improper Authorization",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/912234"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/issues/12"
},
{
"tags": [
"patch"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/commit/d984d172dceca907f8b447efbdb06dc233f7938d"
},
{
"tags": [
"product"
],
"url": "https://github.com/jaychouchannel/Tourism-Management-System/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T13:00:10.000Z",
"value": "VulDB entry last update"
}
],
"title": "jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90520",
"datePublished": "2026-09-13T12:30:10.123Z",
"dateReserved": "2026-09-12T10:54:50.270Z",
"dateUpdated": "2026-09-20T00:35:31.442Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90518 (GCVE-0-2026-90518)
Vulnerability from cvelistv5 – Published: 2026-09-13 12:00 – Updated: 2026-09-14 15:32 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403105 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403105/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90518 | third-party-advisory |
| https://vuldb.com/submit/912176 | third-party-advisory |
| https://github.com/wakakakaaaaha/vuln/issues/3 | exploitissue-tracking |
| https://phpgurukul.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| PHPGurukul | Bank Locker Management System |
Affected:
1.0
cpe:2.3:a:phpgurukul:bank_locker_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90518",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:29:59.232116Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:32:49.252Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:phpgurukul:bank_locker_management_system:*:*:*:*:*:*:*:*"
],
"product": "Bank Locker Management System",
"vendor": "PHPGurukul",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Racosmo (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T12:00:11.938Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403105 | PHPGurukul Bank Locker Management System sidebar.php access control",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403105"
},
{
"name": "VDB-403105 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403105/cti"
},
{
"name": "CVE-2026-90518 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90518"
},
{
"name": "Submit #912176 | PHPGurukul Bank Locker Management System (BLMS) v1.0 broken access control",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/912176"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/wakakakaaaaha/vuln/issues/3"
},
{
"tags": [
"product"
],
"url": "https://phpgurukul.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T11:36:42.000Z",
"value": "VulDB entry last update"
}
],
"title": "PHPGurukul Bank Locker Management System sidebar.php access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90518",
"datePublished": "2026-09-13T12:00:11.938Z",
"dateReserved": "2026-09-12T09:31:34.097Z",
"dateUpdated": "2026-09-14T15:32:49.252Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90507 (GCVE-0-2026-90507)
Vulnerability from cvelistv5 – Published: 2026-09-13 09:30 – Updated: 2026-09-14 15:36 Unsupported When Assigned| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403095 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403095/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90507 | third-party-advisory |
| https://vuldb.com/submit/895270 | third-party-advisory |
| https://gist.github.com/Galaxync/26062162d9cc2755… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| vvbbnn00 | WARP-Clash-API |
Affected:
c7bf2360073959861219b422e51ae86411051b46
cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90507",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:36:47.435793Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:36:59.196Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*"
],
"modules": [
"Subscription Handler"
],
"product": "WARP-Clash-API",
"vendor": "vvbbnn00",
"versions": [
{
"status": "affected",
"version": "c7bf2360073959861219b422e51ae86411051b46"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Galaxyn (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T09:30:09.733Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403095 | vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403095"
},
{
"name": "VDB-403095 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403095/cti"
},
{
"name": "CVE-2026-90507 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90507"
},
{
"name": "Submit #895270 | vvbbnn00 (https://github.com/vvbbnn00) WARP-Clash-API latest (main/master branch) CWE-284 (Improper Access Control / Broken Access Control - autho",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/895270"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/Galaxync/26062162d9cc27550795cdc100da2dcb"
}
],
"tags": [
"unsupported-when-assigned"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T10:52:13.000Z",
"value": "VulDB entry last update"
}
],
"title": "vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90507",
"datePublished": "2026-09-13T09:30:09.733Z",
"dateReserved": "2026-09-12T08:46:54.990Z",
"dateUpdated": "2026-09-14T15:36:59.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90501 (GCVE-0-2026-90501)
Vulnerability from cvelistv5 – Published: 2026-09-13 08:00 – Updated: 2026-09-16 13:57| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403089 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403089/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90501 | third-party-advisory |
| https://vuldb.com/submit/892904 | third-party-advisory |
| https://github.com/ArrestX/vhr-advisories/blob/ma… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90501",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T13:57:45.816335Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T13:57:56.833Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*"
],
"product": "vhr",
"vendor": "lenve",
"versions": [
{
"status": "affected",
"version": "1.0-SNAPSHOT"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "huluwa888 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T08:00:10.471Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403089 | lenve vhr HrMapper.xml HrInfoController.updateHr privileges management",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403089"
},
{
"name": "VDB-403089 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403089/cti"
},
{
"name": "CVE-2026-90501 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90501"
},
{
"name": "Submit #892904 | lenve vhr 1.0-SNAPSHOT Improper Input Validation",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/892904"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/ArrestX/vhr-advisories/blob/main/advisories/VHR-VULN-001-mass-assignment-privesc.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T10:29:30.000Z",
"value": "VulDB entry last update"
}
],
"title": "lenve vhr HrMapper.xml HrInfoController.updateHr privileges management",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90501",
"datePublished": "2026-09-13T08:00:10.471Z",
"dateReserved": "2026-09-12T08:24:13.076Z",
"dateUpdated": "2026-09-16T13:57:56.833Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation MIT-1
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Mitigation MIT-17
Strategy: Environment Hardening
Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.
No CAPEC attack patterns related to this CWE.