Junglewise Threat Intelligence

CVE-2026-90840: PHPGurukul Blood Donor Management System authentication bypass in admin controllers

CVE-2026-90840 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Phpgurukul Blood Donor Management System. Vendors: Phpgurukul.

Executive brief

PHPGurukul Blood Donor Management System is a web application used to manage blood donations and donors. The admin dashboard controllers lack proper authentication checks, allowing an unauthenticated attacker to remotely access and manipulate sensitive administrative functions without valid login credentials. This could lead to unauthorized modification of donor records, blood inventory, or system settings.

Technical details

The vulnerability is an authentication bypass in the __construct method of /application/controllers/admin/Dashboard.php and other admin controllers in the CodeIgniter-based application. The root cause is missing or improperly implemented authentication validation in the constructor, allowing direct access to admin functions without session verification. The attack is network-accessible and requires no authentication or user interaction. An attacker can exploit this to gain unauthorized administrative access, execute arbitrary actions, and access or modify sensitive data. No patch information is currently available from the vendor.

Affected products

  • PHPGurukul Blood Donor Management System 1.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory: CVE-2026-90840 published

References

Related threats