A missing authorization vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the file /admin/session.php, where manipulation of the argument ID bypasses authorization checks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a web-based academic scheduling application. The vulnerability has been assigned CVE-2026-85512 and documented on NVD and VulDB. No patch or mitigation details are currently mentioned in the article. The public availability of the exploit raises the criticality level significantly.