PatchDay Alert

CVE

CVE-2026-8083

0field notes · 1digest CVSS 7.3


Daily digests

An attacker can remotely inject SQL through the user-save endpoint in SourceCodester Pharmacy Sales and Inventory System 1.0. No authentication appears to be required, and a public exploit already exists. If you're running this app, anyone on the network can read or modify your database.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.