CVE-2026-76049Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 108-1808-19
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-181
Disclosure1
2026-08-191
Exploit1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Exploit

    CVE-2026-76049 - SQLi in SourceCodester Simple Online Food Ordering System 1.0 via /admin/ajax.php. Remote exploit public, unpatched. CVSS 7.3. Update or isolate now. #CVE #infosec #SQLi https://www.valtersit.com/cve/CVE-2026-76049/ #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The tweet announces a publicly exploitable SQL injection (CVE‑2026‑76049) with a CVSS 7.3 score, urges immediate patching or isolation, and links to a CVE detail page, though it does not provide exploit code itself.

    0000053
    1.0K followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Disclosure

    Public VulDB reports three remotely reachable SQL injection flaws (CVE-2026-76048, CVE-2026-76049, CVE-2026-76050) in SourceCodester Simple Online Food Ordering System 1.0 on /admin/ajax.php, rated critical with exploits said to be available. https://cyberresearch.us/research/sourcecodester-simple-online-food-ordering-2026-08/

    Post summary

    The post announces three critical, remotely reachable SQL injection vulnerabilities in SourceCodester Simple Online Food Ordering System 1.0, noting that exploits are reportedly available but providing no PoC or patch details.

    0000049
    69 followersView on X

Explore more