SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86292

HIGH · CVSS 7.3 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the user creation functionality of the SourceCodester Simple Traffic Offense System 1.0 allows for remote exploitation due to missing authentication when manipulating the argument position in the saveuser.php file. This high-severity issue could enable unauthorized access to user accounts, posing a significant risk to the integrity and security of the system. Organizations using this software should prioritize immediate remediation to mitigate potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86292
Severity
HIGH
CVSS
7.3
EPSS
0.51%

Original NVD Description

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now public and may be used.