DevSecOps Toolkit

CVE record

CVE-2026-31070

CRITICALCVSS 9.8

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body

Vulnerability metadata

Published
2026-05-19T10:46:20.363Z
Modified
2026-05-20T08:46:40.350Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References