CVE-2026-14778General

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The name of the affected product appears to have a typo in it.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Exploit Tool / Code · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 107-0607-07
Signal classification2 categories
General
150.0%
Exploit
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-061
General1
2026-07-071
Exploit1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-14778 A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll… https://www.cve.org/CVERecord?id=CVE-2026-14778

    Post summary

    The text announces a CVE for SourceCodester Online Examination & Learning Management System 1.0, providing only a brief description and a reference to the CVE record, with no further technical or exploit details.

    00010733
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 HIGH severity CVE-2026-14778 (CVSS 7.3) affects SourceCodester Online Examination & LMS 1.0. Improper authorization in /ajax_enroll[.]php allows remote exploitation. Exploit publicly available. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/JVoyJ1N99T

    Post summary

    CVE-2026-14778 is a high‑severity Remote Code Execution vulnerability in SourceCodester LMS 1.0, exposed via improper authorization on /ajax_enroll.php, with a publicly available exploit and an urgent patch recommendation.

    0000077
    66 followersView on X

Explore more