PatchSiren cyber security CVE debrief
CVE-2026-86298 SourceCodester CVE debrief
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This vulnerability could allow attackers to manipulate data or extract sensitive information. Defenders should assess exposure and prioritize patching or mitigation. The CVE record and NVD entry provide details on the vulnerability.
- Vendor
- SourceCodester
- Product
- Class and Exam Timetabling System
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for SourceCodester Class and Exam Timetabling System 1.0 deployments should assess exposure and prioritize patching or mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify potential exposure to SQL injection attacks and assess the impact of a successful attack on data confidentiality and integrity.
Why it matters
Defenders should care about CVE-2026-86298 because it represents a SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0, which could allow attackers to manipulate data or extract sensitive information.
- Verify potential exposure to SQL injection attacks
- Assess the impact of a successful attack on data confidentiality and integrity
- Prioritize patching or mitigation to prevent exploitation
- Monitor for potential attacks and anomalies
Technical summary
A SQL injection vulnerability exists in the /delete_subject.php file of SourceCodester Class and Exam Timetabling System 1.0. The vulnerability is caused by improper sanitization of user input in the ID argument. This could allow attackers to manipulate data or extract sensitive information. The exploit has been released to the public and may be used for attacks. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available. The vulnerability could allow attackers to manipulate data or extract sensitive information.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.
Recommended defensive actions
- Verify the presence of this vulnerability in your systems
- Apply patches or mitigations as available
- Monitor for potential attacks
- Verify potential exposure to SQL injection attacks
- Assess the impact of a successful attack on data confidentiality and integrity
- Prioritize patching or mitigation to prevent exploitation
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected systems and versions is not clearly stated. The vulnerability is caused by improper sanitization of user input in the ID argument. There are limited details on the affected scope, severity, and vendor guidance. Defenders should verify potential exposure to SQL injection attacks and assess the impact of a successful attack on data confidentiality and integrity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86298 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86298
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86298 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86298
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mexics2/vulnerability-report/issues/5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-86298
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/906517
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399460
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399460/cti
-
Source reference
Unverified legacy reference
URL: https://www.sourcecodester.com/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.