---
id: CVE-2026-90858
title: >-
  A flaw has been found in subhajitkhan online-clinic-management-system up to
  e9ee77a8827a1446220fa07ee693dc4d9a29a578
summary: >-
  A flaw has been found in subhajitkhan online-clinic-management-system up to
  e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is
  the function session_start of the file adminappview.php. Executing a
  manipulation of …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
vendor: subhajitkhan
product: online-clinic-management-system
affected:
  - online-clinic-management-system e9ee77a8827a1446220fa07ee693dc4d9a29a578
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:19:38.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90858'
references:
  - url: 'https://github.com/subhajitkhan/online-clinic-management-system/'
    label: cna@vuldb.com
  - url: 'https://github.com/subhajitkhan/online-clinic-management-system/issues/4'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90858'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/927291'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403415'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403415/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T17:55:02.799325Z'
epss: 0.00309
epssPercentile: 0.23915
ingestedAt: '2026-09-15T04:20:24.669Z'
---

## Overview

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
