Loading market data...
← Back to CVE feed

CVE-2026-31070

UNKNOWN View on NVD ↗

Description

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body

Published: May 19, 2026 16:16 UTC Modified: May 19, 2026 18:04 UTC