Hard-Coded Credentials Vulnerability in SourceCodester Learning Management System
CVE-2026-86276
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 September 2026
Badges
What is CVE-2026-86276?
A security flaw has been identified in the SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0, specifically affecting the processing of the db.php file. This vulnerability allows for the potential exploitation of hard-coded credentials, which can be leveraged remotely. Attackers could manipulate the functionality to expose sensitive credential information, making this a critical concern for system administrators and users alike.
Affected Version(s)
Syllabus-Aligned Learning Management & Examination System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
