CVE-2026-86673
Deferred Deferred - Pending Action

Hard-Coded Credentials in Ningzichun Student Management System

Vulnerability report for CVE-2026-86673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulDB

Description

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ningzichun student_management_system to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a hard-coded credential issue in the ningzichun Student Management System. The flaw exists in the mysqli_connect function of the config/database.php file, allowing remote attackers to potentially gain unauthorized access due to exposed credentials.

Impact Analysis

An attacker could exploit this to gain access to sensitive data stored in the system, such as student records or administrative functions. Since credentials are hard-coded, changing them may not be straightforward, increasing the risk of prolonged unauthorized access.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Immediately review the config/database.php file in the ningzichun Student Management System for hard-coded credentials. Remove any hard-coded database credentials and replace them with secure configuration methods such as environment variables or a secure configuration management system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86673. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart