CVE-2026-90566 Details
Description
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability has been identified in Rizwan17's inventory management system, specifically in the registration handler component, up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The issue arises in the createUserAccount function within register.php, where the usertype argument can be manipulated to bypass authorization controls. This flaw enables remote attackers to create admin accounts without proper validation. The vulnerability has been publicly disclosed and exploited.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://github.com/Rizwan17/inventory-management-system/issues/16 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-90566 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/912565 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403151 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403151/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rizwan17 inventory-management-system | bfe78a330d01bb26b9daec5dc9ecd5c77900e03f |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion