Improper Authorization Vulnerability in Neethuharii CafeManagement Software
CVE-2026-96556
Key Information:
- Vendor
Neethuharii
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-96556?
A significant flaw has been identified in Neethuharii CafeManagement, specifically within the addcashier function of the AddCashierCode.php file. This vulnerability arises from the manipulation of parameters such as uname, pass, role, and status, potentially leading to unauthorized access. Attackers can exploit this weakness remotely, making it a critical risk for users of the system. Despite the timely notification of the vendor regarding this issue, no response has been recorded. Organizations using this software should take immediate action to assess their risk and implement necessary safeguards.
Affected Version(s)
CafeManagement 5f743043a9a04f903678697f061d2e220e544c09
CafeManagement 66c837020e25af4866cb69b23ec3af4e0e1510c9
CafeManagement f80fe4442d5e15af5c78df3f22177a131c1e6f32
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
