A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-11552

CVE-2026-11552: SourceCodester LMS Auth Bypass Vulnerability

CVE-2026-11552 is an authentication bypass flaw in SourceCodester Online Examination & Learning Management System affecting import_users.php with hard-coded credentials. This article covers technical details, impact, and mitigation.

Published: June 11, 2026

CVE-2026-11552 Overview

CVE-2026-11552 is a hard-coded password vulnerability affecting SourceCodester Online Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System version 1.0. The same product is distributed under two distinct names. The flaw resides in the import_users.php script, where the raw_password argument is set to the hard-coded value CICT_2026. An unauthenticated attacker can exploit the issue remotely. The exploit has been publicly disclosed, increasing the likelihood of opportunistic abuse against exposed instances. The weakness is classified under [CWE-255] (Credentials Management Errors).

Critical Impact

Any actor who knows the hard-coded password CICT_2026 can authenticate as imported users, leading to unauthorized account access across affected deployments.

Affected Products

  • SourceCodester Online Examination & Learning Management System 1.0
  • SourceCodester Syllabus-aligned Learning Management and Examination System 1.0
  • Both names refer to the same distributed codebase

Discovery Timeline

  • 2026-06-08 - CVE-2026-11552 published to NVD
  • 2026-06-09 - Last updated in NVD database

Technical Details for CVE-2026-11552

Vulnerability Analysis

The vulnerability exists in the user import workflow implemented in import_users.php. When the application provisions accounts through this import routine, it assigns the static string CICT_2026 to the raw_password field rather than generating a per-user secret or requiring a credential reset on first login. Because the password is embedded in source code, every imported account shares the same predictable credential.

An attacker reaching the login interface over the network can authenticate to any imported account by supplying CICT_2026. No prior authentication, user interaction, or special privilege is required. Successful login yields access to the targeted user's data and any application functions tied to that role, including instructor or administrative capabilities depending on which accounts were imported.

The issue is amplified by public disclosure of the exploit, which removes the cost of reverse engineering. Operators running either named distribution are equally affected because both ship the same import_users.php logic.

Root Cause

The root cause is the use of a hard-coded password literal inside server-side PHP code. The import routine fails to generate randomized credentials, prompt for a unique password, or enforce a forced password change on first login.

Attack Vector

Exploitation is performed remotely over the network against the application's authentication endpoint. The attacker enumerates usernames created through import_users.php and submits the known password CICT_2026 to gain access. The attack requires no privileges and no user interaction.

No verified proof-of-concept code is published in the references. See the VulDB entry for CVE-2026-11552 for additional disclosure details.

Detection Methods for CVE-2026-11552

Indicators of Compromise

  • Successful authentication events using the password value CICT_2026 against accounts created by import_users.php.
  • Repeated login attempts from a single source IP iterating through imported usernames.
  • Session activity from imported accounts originating from unexpected geographic locations or hosting providers.

Detection Strategies

  • Perform static review of import_users.php to confirm the presence of the CICT_2026 literal assigned to raw_password.
  • Query the user database for rows where the stored password hash matches the hash of CICT_2026, which identifies accounts still using the default credential.
  • Correlate web server access logs for POST requests to the login handler that immediately follow access to import endpoints.

Monitoring Recommendations

  • Enable verbose authentication logging on the application and forward logs to a centralized SIEM for analysis.
  • Alert on bulk successful logins across multiple accounts from a shared source within a short time window.
  • Track first-login activity for imported users and flag sessions where the password has not been rotated.

How to Mitigate CVE-2026-11552

Immediate Actions Required

  • Remove the hard-coded CICT_2026 value from import_users.php and replace it with a cryptographically random password generated per user.
  • Force a password reset for every account previously created through the import workflow.
  • Restrict access to the application's authentication endpoint to trusted networks until remediation is complete.

Patch Information

No vendor patch is referenced in the published advisory. Administrators should track the SourceCodester project resources and the VulDB vulnerability record #369162 for any subsequent fix. Until an official patch is released, source-level modification of import_users.php is required to eliminate the static credential.

Workarounds

  • Modify the import logic to generate unique random passwords and deliver them through an out-of-band channel.
  • Set a password_must_change flag on imported accounts so users are required to choose a new password at first login.
  • Disable the import feature entirely if it is not in active use, and remove import_users.php from the web root.
bash
# Identify accounts still using the hard-coded default by hashing the known value
# and comparing against stored hashes (adjust column and table names to your schema)
mysql -u root -p lms_db -e "SELECT id, username FROM users WHERE password = MD5('CICT_2026') OR password = SHA1('CICT_2026');"

# Force password reset on affected accounts
mysql -u root -p lms_db -e "UPDATE users SET force_password_change = 1 WHERE password IN (MD5('CICT_2026'), SHA1('CICT_2026'));"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechSourcecodester

  • SeverityMEDIUM

  • CVSS Score5.5

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-255
  • Technical References
  • VulDB CVE-2026-11552

  • VulDB Submission #836751

  • VulDB Vulnerability #369162

  • VulDB CTI for #369162

  • SourceCodester Security Resources
  • Related CVEs
  • CVE-2026-9603: eDoc Appointment System Auth Bypass Flaw

  • CVE-2026-11482: Class & Exam Timetabling SQLi Flaw

  • CVE-2026-10704: Pizzafy E-Commerce System SQLi Vulnerability

  • CVE-2026-9564: Hospital Patient Records System XSS Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English