A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The flaw exists in the file /voting/ajax.php?action=save_category, where manipulation of the 'Category' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a web-based voting application distributed by SourceCodester. No authentication details are specified, suggesting the endpoint may be accessible without prior authentication. The vulnerability has been assigned CVE-2026-86290 and is listed in the NVD database. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.