CVE-2026-86267

A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

  • Published Sep 7, 2026
  • CVSS 2.1 low
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86267 at the National Vulnerability Database