SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90518

MEDIUM · CVSS 6.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A vulnerability in the PHPGurukul Bank Locker Management System 1.0 allows for improper access controls due to manipulation of the UserType argument in the sidebar.php file. This could enable remote attackers to gain unauthorized access to sensitive functionalities. Organizations using this system should prioritize addressing this issue to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90518
Severity
MEDIUM
CVSS
6.3
EPSS
N/A

Original NVD Description

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.