A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the /delete_user_account.php file, where manipulation of the 'ID' argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects an unknown functionality within the targeted file. Attackers could potentially manipulate database queries to gain unauthorized access or extract sensitive data. The issue has been documented in VulDB and tracked under CVE-2026-86210. Users of the affected system are advised to apply patches or mitigations promptly.