CVE-2026-86217

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

  • Published Sep 6, 2026
  • CVSS 5.5 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86217 at the National Vulnerability Database