Junglewise Threat Intelligence

CVE-2026-86211: rabindralamsal inventory-management-system SQL injection in login

CVE-2026-86211 · Severity: high · CVSS 7.3 · Published 2026-09-06

Technologies: Rabindralamsal Inventory Management System.

Executive brief

The inventory-management-system is a web-based application for managing inventory. An unauthenticated attacker can bypass login and gain unauthorized access by injecting SQL code through the username or password fields, potentially allowing them to extract sensitive data, modify records, or take control of the system.

Technical details

The vulnerability is a SQL injection flaw in the login functionality of index.php. The application directly concatenates user-supplied username and password parameters into SQL queries without using parameterized queries or input validation/escaping. An unauthenticated attacker can exploit this remotely by submitting specially crafted SQL payloads in the POST request to index.php, allowing arbitrary SQL execution. This can lead to authentication bypass, data exfiltration, or full database compromise. The application uses MD5 hashing but applies it after the vulnerable concatenation step, making the vulnerability exploitable regardless of password hashing.

Affected products

  • rabindralamsal inventory-management-system 1.0.0

Timeline

  • 2026-07-20: disclosed
  • 2026-09-06: advisory

References