CVE-2026-90840

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.

  • Published Sep 15, 2026
  • CVSS 5.5 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90840 at the National Vulnerability Database