CVE-2026-3762

HIGH

SourceCodester CDMS 1.0/3.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the argument manager_id leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 7.3
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
lerouxyxchire/client_database_management_system 1.0
Published Mar 08, 2026
Tracked Since Mar 09, 2026