CVE-2026-2174

HIGH

Contact Management System 1.0 - Improper Authentication via CRUD Endpoint ID Argument

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.344875
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.344875
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.749262
Product product
https://code-projects.org/

Scores

CVSS v3 7.3
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
fabian/contact_management_system 1.0
Published Feb 08, 2026
Tracked Since Feb 18, 2026