AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-14778

HIGH · CVSS 7.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

A vulnerability in the Enrollment Management component of SourceCodester Online Examination & Learning Management System 1.0 allows for improper authorization due to manipulation of the student_id, schedule_id, and action parameters in the /ajax_enroll.php file. This high-severity flaw can be exploited remotely, potentially allowing unauthorized access to sensitive functionalities. Organizations using this system should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14778
Severity
HIGH
CVSS
7.3
EPSS
0.29%

Original NVD Description

A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The name of the affected product appears to have a typo in it.