Description
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Improper Authentication
Action: Apply Patch
AI Analysis

Impact

A remote attacker can manipulate the user_id argument used by the Auth Guard component of SourceCodester Drug Recommendation System, causing the system to authenticate without proper verification. This flaw is classified as improper authentication (CWE-287) and can allow unauthorized users to access protected resources and functions that should be restricted.

Affected Systems

The vulnerability affects SourceCodester Drug Recommendation System version 1.0. The issue is present in the Auth Guard function within that release, and no other versions are listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the exploit is remotely executable with publicly available code. EPSS data is not available and the issue is not in the CISA KEV catalog, but the remote nature of the attack and the lack of authentication imply a significant risk to confidentiality and integrity if an unauthenticated user gains access.

Generated by OpenCVE AI on October 6, 2026 at 05:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website for an updated version of the Drug Recommendation System that addresses the authentication flaw
  • If an update is not yet available, ensure that any user_id input is validated server‑side and that session management requires proper authentication tokens
  • Consider temporarily restricting or disabling the affected Auth Guard functionality until a patch can be applied

Generated by OpenCVE AI on October 6, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
Title SourceCodester Drug Recommendation System Auth Guard improper authentication
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-287
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T04:15:13.691Z

Reserved: 2026-10-05T18:23:20.356Z

Link: CVE-2026-105704

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T05:16:37.663

Modified: 2026-10-06T05:16:37.663

Link: CVE-2026-105704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T05:30:18Z

Weaknesses