PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105170 kishor-23 CVE debrief

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely.

Vendor
kishor-23
Product
food-waste-management-system
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for the kishor-23 food-waste-management-system should assess exposure and prioritize verification of the presence of this vulnerability in their inventory. They should also consider compensating controls for authentication and review relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, defenders should track exceptions, retest remediated assets, and close the item only after evidence is

Why it matters

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as the exploit has been made available to the public and could be used for attacks. The vulnerability is caused by a weakness in the Admin Signup component of the kishor-23 food-waste-management-system, which could lead to missing authentication.

  • Verify authentication mechanisms for Admin Signup
  • Assess exposure to remote attacks
  • Consider compensating controls for authentication

Technical summary

The vulnerability is caused by a weakness in the Admin Signup component of the kishor-23 food-waste-management-system. The exploit has been made available to the public and could be used for attacks. This weakness leads to missing authentication, which can be exploited remotely. The project was informed of the problem early through an issue report but has not responded yet. No version details of affected nor updated releases are available due to the continuous delivery with rolling releases used by this product. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as the exploit has been made available to the public.

Recommended defensive actions

  • Verify the presence of this vulnerability in your inventory
  • Assess exposure of the Admin Signup component
  • Consider compensating controls for authentication
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The vendor has not responded to the issue report. Defenders should verify the presence of this vulnerability in their inventory and assess exposure, as the exploit has been made available to the public and could be used for attacks. The vulnerability is caused by a weakness in the Admin Signup component of the kishor-23 food-waste-management-system, which could lead to missing authentication. Limited source detail is available, so defenders should focus

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105170 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105170

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105170 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105170

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.