PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86298 SourceCodester CVE debrief

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This vulnerability could allow attackers to manipulate data or extract sensitive information. Defenders should assess exposure and prioritize patching or mitigation. The CVE record and NVD entry provide details on the vulnerability.

Vendor
SourceCodester
Product
Class and Exam Timetabling System
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for SourceCodester Class and Exam Timetabling System 1.0 deployments should assess exposure and prioritize patching or mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify potential exposure to SQL injection attacks and assess the impact of a successful attack on data confidentiality and integrity.

Why it matters

Defenders should care about CVE-2026-86298 because it represents a SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0, which could allow attackers to manipulate data or extract sensitive information.

  • Verify potential exposure to SQL injection attacks
  • Assess the impact of a successful attack on data confidentiality and integrity
  • Prioritize patching or mitigation to prevent exploitation
  • Monitor for potential attacks and anomalies

Technical summary

A SQL injection vulnerability exists in the /delete_subject.php file of SourceCodester Class and Exam Timetabling System 1.0. The vulnerability is caused by improper sanitization of user input in the ID argument. This could allow attackers to manipulate data or extract sensitive information. The exploit has been released to the public and may be used for attacks. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available. The vulnerability could allow attackers to manipulate data or extract sensitive information.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.

Recommended defensive actions

  • Verify the presence of this vulnerability in your systems
  • Apply patches or mitigations as available
  • Monitor for potential attacks
  • Verify potential exposure to SQL injection attacks
  • Assess the impact of a successful attack on data confidentiality and integrity
  • Prioritize patching or mitigation to prevent exploitation
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected systems and versions is not clearly stated. The vulnerability is caused by improper sanitization of user input in the ID argument. There are limited details on the affected scope, severity, and vendor guidance. Defenders should verify potential exposure to SQL injection attacks and assess the impact of a successful attack on data confidentiality and integrity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86298 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86298

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86298 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86298

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.