CVE-2026-2199
Published: 09 February 2026
Summary
CVE-2026-2199 is a medium-severity Injection (CWE-74) vulnerability in Fabian Online Reviewer System. Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 24.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2026-2199 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0. The flaw affects an unknown function within the file /reviewer/system/system/admins/manage/users/user-delete.php, where manipulation of the ID argument enables the injection. It was published on 2026-02-09 and carries a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), linked to CWEs 74 and 89.
The vulnerability can be exploited remotely by unauthenticated attackers with low complexity and no user interaction required. Successful exploitation allows limited impacts on confidentiality, integrity, and availability, potentially enabling unauthorized data access, modification, or disruption via SQL injection.
Advisories and details are available in references including code-projects.org, a GitHub issue at github.com/6Justdododo6/CVE/issues/3, and multiple VulDB entries (vuldb.com/?ctiid.344902, vuldb.com/?id.344902, vuldb.com/?submit.750019).
An exploit for this vulnerability has been released publicly and may be used in attacks.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-6899
Vulnerability details
A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely.…
more
The exploit has been released to the public and may be used for attacks.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Direct remote SQL injection in a web application enables exploitation of public-facing apps (T1190).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation of the ID parameter in user-delete.php to block SQL injection payloads before they reach the database.
Mandates timely patching or code fixes for the publicly disclosed SQL injection flaw in the Online Reviewer System.
Limits database privileges of the application account so that a successful injection via the ID argument yields minimal data impact.