Junglewise Threat Intelligence

CVE-2026-90566: Rizwan17 inventory-management-system privilege escalation in registration

CVE-2026-90566 · Severity: high · CVSS 7.3 · Published 2026-09-13

Technologies: Rizwan17 Inventory Management System.

Executive brief

Rizwan17's inventory management system is a web application used for managing product inventory and user accounts. An unauthenticated attacker can register a new user account and assign themselves an "Admin" role without authorization, gaining full administrative access to the system. This allows complete compromise of the application and any business data stored within it.

Technical details

The vulnerability is an improper authorization flaw in the registration handler component (register.php and includes/process.php). The createUserAccount() function in includes/user.php accepts a client-controlled "usertype" parameter from POST data without validation, allowing an unauthenticated attacker to register a new account and set the usertype to "Admin" instead of being restricted to the least-privileged "Other" role. An attacker can submit a registration request with usertype=Admin to gain immediate administrative access. The vulnerability requires network access and no authentication or user interaction, making it trivially exploitable. Proof-of-concept exploitation has been publicly disclosed, allowing direct admin account creation and full system compromise.

Affected products

  • Rizwan17 inventory-management-system up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

Timeline

  • 2026-08-01: disclosed
  • 2026-09-13: other: CVE published

References