CVE-2026-86277 Details
Description
A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
A vulnerability allowing authorization bypass through insecure direct object references has been identified in SourceCodester Syllabus-Aligned Learning Management and Examination System version 1.0. The issue resides in the file delete_exam.php, where the manipulation of the 'id' parameter enables unauthorized access to functions. This vulnerability can be exploited remotely and has been publicly disclosed.
To address this vulnerability, implement ownership verification before allowing any deletions or modifications. Additionally, add authentication checks to view.php and enrollment verification to take_exam.php.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-04-IDOR-Broken-Access-Control.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-86277 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/904877 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399438 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399438/cti | [email protected] | Content Wall |
| https://www.sourcecodester.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SourceCodester Syllabus-Aligned Learning Management & Examination System | 1.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion