CVE-2026-9603 Details
Description
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
A missing authorization vulnerability exists in SourceCodester eDoc Doctor Appointment System version 1.0. The issue is located in the admin/delete-session.php file, where the ID parameter can be manipulated without proper authorization checks. This vulnerability allows remote, unauthenticated attackers to delete appointment or session records by exploiting the flawed authorization process.
To address this vulnerability, it is recommended to enforce authentication and authorization checks for all administrative endpoints, validate user roles before processing delete operations, restrict direct access to sensitive administrative functionality, and implement centralized access control middleware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NARKHEDE-VAIBHAV/poc/blob/main/CVE-2026-9603-Missing-Authorization/Advisory.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/NARKHEDE-VAIBHAV/poc/blob/main/CVE-2026-9603-Missing-Authorization/poc.sh | [email protected] | Exploit |
| https://vuldb.com/submit/817935 | [email protected] | Permission Required |
| https://vuldb.com/vuln/365676 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/365676/cti | [email protected] | AdvisoryPermission Required |
| https://www.sourcecodester.com/ | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SourceCodester eDoc Doctor Appointment System | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |
Volerion