CVE-2026-9603: SourceCodester eDoc Doctor Appointment System delete-session.php authorization

Published May 26, 2026
·
Updated

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Affected Software

1 affected component
Sourcecodester eDoc Doctor Appointment System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure /admin/delete-session.php performs server-side authorization checks on the ID argument: validate input, confirm the authenticated user has permission to delete the referenced session, and deny the request if authorization fails.

    SourceCodester eDoc Doctor Appointment System (admin/delete-session.php) authorization_check_on_ID_parameter = enabled / validate ownership and permissions
  2. Compensating control

    Restrict remote access to the /admin/ area (including delete-session.php) using network controls: limit to trusted IPs or VPN, enforce strong authentication, and/or place the admin interface behind a firewall or WAF to block unauthorized requests.

  3. Operational

    Review web and application logs for requests to /admin/delete-session.php (and manipulations of the ID parameter) to detect possible exploitation. If unauthorized deletions are found, investigate impact, restore affected data from backups as needed, and rotate any credentials or sessions that may have been exposed.

Event History

May 26, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·06:35 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-9603?

CVE-2026-9603 has a medium severity rating of 6.5.

2

How does CVE-2026-9603 affect the SourceCodester eDoc Doctor Appointment System?

CVE-2026-9603 affects the file /admin/delete-session.php, allowing for missing authorization due to manipulation of the argument ID.

3

Can CVE-2026-9603 be exploited remotely?

Yes, CVE-2026-9603 allows for remote exploitation.

4

What impact does CVE-2026-9603 have on system integrity?

CVE-2026-9603 leads to a potential loss of integrity as it allows unauthorized operations to be performed.

5

How can the vulnerability CVE-2026-9603 be mitigated?

To mitigate CVE-2026-9603, ensure proper authorization checks are implemented in the /admin/delete-session.php file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203