CVE-2026-94048

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-20: 209-20
Referenced assets2 URLs
Full discourse2 posts
  • SecNews@SecNews_GR

    CodeAstro QR Code Attendance: Κρίσιμη ευπάθεια με δημόσιο exploit https://www.secnews.gr/734580/codeastro-qr-code-attendance-cve-2026-94048/?fsp_sid=13691

    00000156
    7.0K followersView on X
  • CVE@CVEnew

    CVE-2026-94048 A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The… https://www.cve.org/CVERecord?id=CVE-2026-94048

    00000906
    58.1K followersView on X

Explore more