A vulnerability has been identified in the light0011 CMS affecting the file App/Home/Model/UserModel.class.php within the Cookie Helper component. The flaw allows an attacker to manipulate the Username argument, leading to improper authentication. The attack can be executed remotely, and a public exploit is already available, increasing the risk of active exploitation. The affected product uses a rolling release model, so no specific version information is disclosed. The project maintainer was notified via an issue report but has not yet responded. The vulnerability is tracked as CVE-2026-86306 and is referenced in both the NVD and VulDB databases.