CVE-2026-31070
The LalanaChami Pharmacy Management System allows anyone to create an account and assign themselves an administrative role. Because the signup API does not validate the role field, attackers can become administrators without authentication. This can give them full control over the system.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
LalanaChami Pharmacy Management System (commit 5c3d028). No specific version numbers are listed, but any deployment of this system that includes the vulnerable signup endpoint is affected.
Real-world impact
An attacker who exploits this flaw can gain administrative privileges, enabling them to view, modify, or delete patient records, alter system settings, and add or remove users. This could lead to data theft, data loss, or unauthorized system changes.
Why this severity
The CVSS score of 9.8 reflects a remote, unauthenticated attack that grants complete confidentiality, integrity, and availability compromise. The attacker can elevate privileges without any credentials, making the vulnerability extremely dangerous.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 19, 2026 · May 19, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.