{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-87922/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rizwan17:inventory_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-87922"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["inventory-management-system (up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f)","inventory-management-system (\u003c= bfe78a330d01bb26b9daec5dc9ecd5c77900e03f)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","auth-bypass","cve-2026-87922"],"_cs_type":"threat","_cs_vendors":["Rizwan17"],"content_html":"\u003cp\u003eA security vulnerability exists in the Rizwan17 inventory-management-system (commits up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f). The flaw is located within the DBOperation.addCategory function in the includes/process.php file, which handles AJAX backend requests. An attacker can manipulate the userid argument to bypass authentication checks, allowing for unauthorized modifications to the inventory categories. Because the project utilizes a rolling release model, no specific version numbers are assigned to the affected or patched code. Publicly available exploit code currently exists for this vulnerability, increasing the risk of active exploitation by remote threat actors. The project maintainers have been notified of the issue but have not yet provided a fix or response.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to add unauthorized categories to the inventory system. This can be used to manipulate business logic, disrupt inventory tracking, or serve as a vector for further unauthorized database interactions within the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at /includes/process.php.\u003c/li\u003e\n\u003cli\u003eAudit the application source code for the DBOperation.addCategory function and implement robust session validation checks for the userid parameter.\u003c/li\u003e\n\u003cli\u003eGiven the lack of a vendor-provided patch, consider placing the inventory-management-system behind a Web Application Firewall (WAF) or restricting access to the includes/ directory via IP-based access control lists (ACLs).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T01:02:56Z","date_published":"2026-09-09T23:02:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-inventory-system-auth-bypass/","summary":"An authentication bypass vulnerability in the AJAX backend of Rizwan17 inventory-management-system allows remote attackers to execute unauthorized category additions via the userid parameter.","title":"Unauthenticated Category Addition in Rizwan17 inventory-management-system","url":"https://feed.craftedsignal.io/briefs/2026-09-inventory-system-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-87922","version":"https://jsonfeed.org/version/1.1"}