MEDIUMVulnerability

CVE-2026-90517

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.

Properties

severity
MEDIUM
score
5.3
cve_id
CVE-2026-90517
signal_observed_at
2026-09-23T04:35:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-09-13T12:17:16.073
last_modified
2026-09-16T15:18:27.863

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Authorization Bypass Through User-Controlled Key
[Weakness]Improper Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90517 — Ninja Signal Threat Intelligence | Ninja Signal