A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the /delete_user.php file, where manipulation of the 'ID' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a web-based academic scheduling application. Attackers could leverage this flaw to manipulate or extract database contents. The vulnerability is tracked as CVE-2026-86209 and has been published on NVD and VulDB. No patch or mitigation details are currently provided in the advisory.