HIGHVulnerability

CVE-2026-86161

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Properties

severity
HIGH
score
7.3
cve_id
CVE-2026-86161
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-06T03:17:17.067
last_modified
2026-09-11T21:17:34.493

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86161 — Ninja Signal Threat Intelligence | Ninja Signal