Back Redpacketsecurity CVE Alert: CVE-2026-86290 – SourceCodester
A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
This is a high operational concern because a public exploit is available, although there is no indication here of active exploitation or inclusion in a known exploited catalogue.
An unauthenticated attacker could potentially manipulate application database queries, exposing voter or administrative data and altering records. Realistic objectives include defacing or disrupting election workflows, tampering with categories or related data, and using recovered database credentials to attack other services. Exploitability is increased by the absence of an authentication or user-interaction requirement.
### Most likely attack path
The likely path is a direct internet request to the affected PHP endpoint, using crafted input with low complexity and no prerequisite access. Scope is unchanged, so the immediate impact should remain within the application and its database; however, stolen credentials, configuration data or database access could enable subsequent lateral movement.
### Who is most exposed
Organisations running the application on publicly reachable, self-hosted PHP/MySQL servers are most exposed, particularly small organisations using default deployments, shared hosting or poorly segregated databases.
Alert on unusual requests to the voting AJAX endpoint, especially encoded quotes, , operators or stacked-query patterns.
Review web and database logs for errors, time-based delays, abnormal query volume or unexpected administrative changes.
Hunt for database accounts or application processes accessing unrelated schemas.
Check for unexplained voter, category, configuration or user-record modifications.
### Mitigation and prioritisation
Apply a vendor-supported fix or upgrade as soon as available; treat unmaintained deployments as requiring replacement.
Until patched, restrict endpoint access, apply WAF parameter allow-listing and remove internet exposure where practical.
Use a tightly scoped database account; rotate potentially exposed credentials and review database privileges.
Back up and integrity-check critical records, then test changes against voting workflows during a controlled maintenance window.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
