CVE-2026-86293

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The exploit has been published and may be used.

  • Published Sep 7, 2026
  • CVSS 5.5 medium
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86293 at the National Vulnerability Database