A SQL injection vulnerability has been identified in code-projects Simple Inventory System version 1.0. The flaw exists in the /delete.php file, where the 'ID' argument is improperly handled, allowing an attacker to manipulate SQL queries. The attack can be launched remotely without requiring physical access to the target system. A public exploit has been disclosed, increasing the risk of active exploitation. The vulnerability affects the delete functionality of the inventory management application. No authentication details are specified, suggesting it may be exploitable without credentials. The issue has been assigned CVE-2026-76990 and is tracked in the NVD and VulDB databases. Administrators using this software are advised to apply patches or mitigations immediately. The disclosure includes a security advisory hosted on GitHub detailing the vulnerability.