OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-96603

HIGH · CVSS 7.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability exists in the Admin Handler component of Abdurrab5's online makeup store, specifically in the confirm_logged_in/confirm_user function, which suffers from missing authorization due to improper handling of the adminid argument. This flaw allows remote attackers to exploit the system, potentially gaining unauthorized access to administrative functions. Organizations using this product should prioritize immediate remediation to mitigate the risk of exploitation, especially given the public disclosure of the vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96603
Severity
HIGH
CVSS
7.3
EPSS
0.28%

Original NVD Description

A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure.