Authorization Bypass in Code-Projects Task Management System 1.0
CVE-2026-19345
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 9 August 2026
Badges
What is CVE-2026-19345?
A significant vulnerability has been identified in the Task Management System version 1.0 developed by Code-Projects. The issue lies within the /user/UpdateTaskStatus.php file where a manipulation of the task_id/val parameter can lead to a lack of proper authorization checks. This flaw permits remote attackers to exploit the system without sufficient permissions, thereby compromising the integrity of the application. The exploit has been made publicly available, heightening the risk for users of this product.
Affected Version(s)
Task Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
