CVE-2026-90518: PHPGurukul Bank Locker Management System sidebar.php access control

Published Sep 13, 2026
·
Updated

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Affected Software

1 affected component
Phpgurukul Bank Locker Management System=1.0

Event History

Sep 13, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for review?

Deployments of PHPGurukul Bank Locker Management System 1.0 should be prioritized, particularly where the application is remotely reachable. The affected behavior is associated with sidebar.php and handling of the UserType argument.

2

What does an attacker need to exploit this issue?

The attacker can launch the attack remotely and requires low-level privileges. No user interaction is required, and a public exploit has been released.

3

What is the potential impact of successful exploitation?

Successful exploitation can result in low impact to confidentiality, integrity, and availability through improper access control. The available data does not identify which specific unauthorized functions or records become accessible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203