CVE-2026-86292: SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication
Published Sep 7, 2026
·Updated
A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
1 affected component
Sourcecodester Simple Traffic Offense System=1.0
Event History
Sep 7, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
No prior privileges or user interaction are required. The issue can be initiated remotely by manipulating the position argument in saveuser.php.
2
How urgent is remediation?
The vulnerability is rated high severity with a 7.3 score, and a public exploit is available. Systems running the affected 1.0 release should be treated as exposed where saveuser.php is remotely reachable.