CVE-2026-14622Patch

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-06: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-06: 107-06
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-14622 – Missing Auth in Jairiidriss restaurant-website-php-mysql. #AJAX endpoint /admin/ajax_files allows remote exploitation. #CVSS 7.3. No patch available. Apply workarounds immediately. #CVEAlert #infosec #cybersecurity #sysadmin #developers #SecurityAlert More: https://www.valtersit.com/cve/CVE-2026-14622/

    Post summary

    The post discloses a missing authentication flaw in a restaurant‑website PHP MySQL AJAX endpoint with CVSS 7.3, no patch exists, and users are urged to apply immediate workarounds.

    00000647
    974 followersView on X

Explore more