Vulnerability Description
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://gist.github.com/nedlir/22bf6d1a3a07209be3e343744bc81d51
- https://github.com/LalanaChami/Pharmacy-Mangment-System/blob/5c3d028886311666498
- https://gist.github.com/nedlir/22bf6d1a3a07209be3e343744bc81d51
FAQ
What is CVE-2026-31070?
CVE-2026-31070 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/s...
How severe is CVE-2026-31070?
CVE-2026-31070 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-31070?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.