← Back to overview

A vulnerability identified as CVE-2026-86277 has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0. The vulnerability resides in the file delete_exam.php, where manipulation of the ID argument leads to an authorization bypass (IDOR/Broken Access Control). The flaw allows remote attackers to bypass access controls and potentially delete exam records without proper authorization. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. The vulnerability is remotely exploitable, requiring no physical access. It has been categorized as an Insecure Direct Object Reference (IDOR) issue. No patch or mitigation has been noted in the article. Users of the affected system are at risk until a fix is applied.

Affected products

  • SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

Related CVE's

  • CVE-2026-86277

Categories

  • Identity & Access
  • Web Technologies