CVE-2026-81202

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.

  • Published Aug 26, 2026
  • CVSS 5.5 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-81202 at the National Vulnerability Database