SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90840

HIGH · CVSS 7.3 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the PHPGurukul Blood Donor Management System 1.0 allows for improper authentication through the __construct function in the Dashboard.php file, potentially enabling remote attackers to gain unauthorized access. Given the high severity rating and the availability of public exploits, organizations using this system should prioritize immediate remediation to mitigate the risk of unauthorized access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90840
Severity
HIGH
CVSS
7.3
EPSS
0.41%

Original NVD Description

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.