OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105170

HIGH · CVSS 7.3 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability in the admin/signup.php function of the kishor-23 food-waste-management system allows for remote exploitation due to missing authentication when manipulating the "sign" argument. This weakness poses a high risk as it could enable unauthorized access to administrative functionalities. Organizations using this system should prioritize immediate remediation efforts, especially given the public availability of the exploit and the lack of response from the project maintainers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105170
Severity
HIGH
CVSS
7.3
EPSS
0.40%

Original NVD Description

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.