---
id: CVE-2026-90697
title: >-
  A vulnerability was identified in SourceCodester Inventory Management System
  1.0
summary: >-
  A vulnerability was identified in SourceCodester Inventory Management System
  1.0. This affects an unknown part of the file invoice.php. The manipulation of
  the argument ID leads to authorization bypass. It is possible to initiate the
  att…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-285
  - CWE-639
vendor: SourceCodester
product: Inventory Management System
affected:
  - inventory_management_system 1.0
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:17:30.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90697'
references:
  - url: 'https://gist.github.com/fhewm98/079112d415afa63ed1368a798a352665'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90697'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/916047'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403230'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403230/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:42:13.371206Z'
epss: 0.00238
epssPercentile: 0.15149
ingestedAt: '2026-09-14T15:23:07.464Z'
---

## Overview

A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
