CVE-2026-94048 Details
Description
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.
A broken access control vulnerability allowing privilege escalation has been identified in CodeAstro QR Code Attendance Management System version 1.0. The issue resides in the UserController's save function, where the role_id parameter is improperly validated. This flaw enables an authenticated user with the Administrator role to manipulate user roles, specifically by demoting a Super Administrator and taking control of their account. The vulnerability can be exploited remotely, and the details of the exploitation are now public.
Before performing the UPDATE, the application should verify the current role of the user being modified and reject any attempts to change the role of a Super Administrator by non-Super-Administrators.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://codeastro.com/ | [email protected] | ProductVendor |
| https://github.com/Witiers/CVEs/issues/4 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/cve/CVE-2026-94048 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/949593 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/407977 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/407977/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CodeAstro QR Code Attendance Management System | 1.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion