Description
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Authorization
Action: Assess Impact
AI Analysis

Impact

The CVE references a weakness in the createUserAccount function within register.php of the inventory‑management‑system. By manipulating the usertype argument, an attacker can bypass the system’s authorization checks and register an account with any desired role. This flaw is classified as improper authorization, corresponding to CWE‑266 and CWE‑285.

Affected Systems

The affected product is the Rizwan17 inventory‑management‑system, which uses a rolling release model and provides no distinct version labels beyond the commit identifier bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The vulnerability resides in the Registration Handler component, specifically the createUserAccount function.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. The EPSS score is less than 1%, implying a low probability of exploitation in the wild, yet the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending crafted registration requests that alter the usertype parameter; public exploit code has been released. With no vendor response yet, the attack surface remains wide and an attacker could potentially create privileged accounts if the flaw is exploited.

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any fixes or updated commits released by the project once they address the issue
  • Validate the usertype parameter to accept only authorized values, rejecting any unrecognized role identifiers
  • Restrict access to the registration endpoint using IP filtering or network segmentation

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:27:09.390Z

Reserved: 2026-09-12T15:51:47.111Z

Link: CVE-2026-90566

cve-icon Vulnrichment

Updated: 2026-09-14T15:27:02.862Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T16:16:52.670

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization