CVE-2026-87924: Missing Authentication in Rizwan17 inventory-management-system
CVE-2026-87924 is a medium severity vulnerability in the Rizwan17 inventory-management-system affecting the invoice generation component. It involves missing authentication due to manipulation of the order_date or invoice_no parameters in includes/invoice_bill.php. The vulnerability can be exploited remotely and a public exploit is available. The product uses rolling releases, so specific affected or fixed versions are not provided. The vendor has not yet responded or issued a fix.
AI Analysis
Technical Summary
This vulnerability in Rizwan17 inventory-management-system up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f allows remote attackers to bypass authentication by manipulating the order_date or invoice_no arguments in the includes/invoice_bill.php file related to invoice generation. The issue leads to missing authentication checks, enabling unauthorized access or actions. The product's rolling release model means no explicit versioning is available for affected or patched states. The vulnerability has been publicly disclosed with exploit code available, but no vendor response or patch has been issued as of the publication date.
Potential Impact
An attacker can remotely exploit this vulnerability to bypass authentication controls in the invoice generation component, potentially allowing unauthorized access or manipulation of invoice data. This could lead to unauthorized viewing or modification of sensitive billing information. The CVSS 4.0 score of 6.9 reflects a medium severity with network attack vector, no privileges required, no user interaction, and low impact on confidentiality and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or issued a fix, users should monitor for updates from the Rizwan17 project. Until a patch is available, consider restricting access to the affected component or implementing additional authentication controls as a temporary mitigation.
CVE-2026-87924: Missing Authentication in Rizwan17 inventory-management-system
Description
CVE-2026-87924 is a medium severity vulnerability in the Rizwan17 inventory-management-system affecting the invoice generation component. It involves missing authentication due to manipulation of the order_date or invoice_no parameters in includes/invoice_bill.php. The vulnerability can be exploited remotely and a public exploit is available. The product uses rolling releases, so specific affected or fixed versions are not provided. The vendor has not yet responded or issued a fix.
CVSS v4.0
Score 6.9medium
Affected software
cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Rizwan17 inventory-management-system up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f allows remote attackers to bypass authentication by manipulating the order_date or invoice_no arguments in the includes/invoice_bill.php file related to invoice generation. The issue leads to missing authentication checks, enabling unauthorized access or actions. The product's rolling release model means no explicit versioning is available for affected or patched states. The vulnerability has been publicly disclosed with exploit code available, but no vendor response or patch has been issued as of the publication date.
Potential Impact
An attacker can remotely exploit this vulnerability to bypass authentication controls in the invoice generation component, potentially allowing unauthorized access or manipulation of invoice data. This could lead to unauthorized viewing or modification of sensitive billing information. The CVSS 4.0 score of 6.9 reflects a medium severity with network attack vector, no privileges required, no user interaction, and low impact on confidentiality and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or issued a fix, users should monitor for updates from the Rizwan17 project. Until a patch is available, consider restricting access to the affected component or implementing additional authentication controls as a temporary mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-09T16:11:15.175Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa1e34aacd9273b49f9030b
Added to database: 09/09/2026, 22:52:58 UTC
Last enriched: 09/09/2026, 23:07:46 UTC
Last updated: 09/09/2026, 23:12:02 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.