PatchSiren cyber security CVE debrief
CVE-2026-86222 SourceCodester CVE debrief
A SQL injection vulnerability was found in the SourceCodester Class and Exam Timetabling System 1.0, affecting the function mysqli_query of the file /admin/modal_add_course2.php. This vulnerability allows for SQL injection attacks that can be launched remotely. The exploit has been disclosed to the public and may be used. Defenders and administrators of systems using SourceCodester Class and Exam Timetabling System 1.0, especially those with remote access, should assess exposure and prioritize patching or mitigation.
- Vendor
- SourceCodester
- Product
- Class and Exam Timetabling System
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-06
- Original CVE updated
- 2026-09-06
- Advisory published
- 2026-09-06
- Advisory updated
- 2026-09-06
Who should care
Defenders and administrators of systems using SourceCodester Class and Exam Timetabling System 1.0, especially those with remote access, should assess exposure and prioritize patching or mitigation.
Why it matters
CVE-2026-86222 is a SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 that can be exploited remotely. Defenders should assess exposure, prioritize patching or mitigation, and monitor for potential exploitation attempts.
- Verify potential exposure of systems using SourceCodester Class and Exam Timetabling System 1.0
- Assess remote attack surface for potential exploitation
- Prioritize patching or mitigation for systems with remote access
- Monitor for potential exploitation attempts
Technical summary
The vulnerability affects the function mysqli_query of the file /admin/modal_add_course2.php in SourceCodester Class and Exam Timetabling System 1.0, allowing for SQL injection attacks that can be launched remotely. The attack surface includes systems with remote access to the affected application. Defenders should assess exposure, prioritize patching or mitigation, and monitor for potential exploitation attempts. The vulnerability has been disclosed publicly, increasing the urgency for remediation. The affected product is SourceCodester Class and Exam Timetabling System 1.0, and the vulnerability class is SQL injection. The likely operational impact includes unauthorized data access or modification. The source confidence is limited to the information provided in the CVE record and NVD entry. Defenders should verify the scope of affected systems and versions, and apply patches or mitigations accordingly. Compensating controls, such as input validation and intrusion detection, may be necessary for exposed systems while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Exceptions should be tracked, and remediated assets should be retested before closing the item. Evidence of remediation should be documented. The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the full scope of affected systems and versions. The attack may be launched remotely, and the exploit has been disclosed to the public and may be used. The vulnerability has not been modified since its publication on 2026-09-06T20:17:28.117Z. The CVSS score is 5.5, and the severity is MEDIUM. The vendor needs to review and provide guidance on the affected product and versions. The NVD entry and CVE record provide official details on the vulnerability. The source references provide additional information on the vulnerability. The debrief is based on the supplied source corpus and CVE record. The technical summary focuses on the affected product, vulnerability class, and defensive impact. The evidence notes provide information on the source of
Defensive priority
Assess exposure and prioritize patching or mitigation for systems using the affected SourceCodester Class and Exam Timetabling System 1.0, especially those accessible remotely.
Recommended defensive actions
- Assess exposure of systems using SourceCodester Class and Exam Timetabling System 1.0
- Prioritize patching or mitigation for remotely accessible systems
- Verify inventory for affected systems and apply patches or mitigations
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected systems and versions requires further verification. The SourceCodester Class and Exam Timetabling System 1.0 may have multiple deployments across different environments. Defenders should verify potential exposure by reviewing system inventories and configurations. They should also assess remote attack surface for potential exploitation and prioritize patching or mitigation for systems with remote access. Additionally, defenders should monitor for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86222 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86222
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86222 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86222
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/justconter/_CVE/issues/3
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-86222
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/897748
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399375
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399375/cti
-
Source reference
Unverified legacy reference
URL: https://www.sourcecodester.com/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.