What is CVE-2026-0850?
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Timeline
- 2026-01-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Carmelo Intern Membership Management System
Remediation Steps
- Identify all Plant iT and Brewmaxx deployments in industrial environments
- Apply Schneider Electric security patches addressing privilege escalation
- Implement least-privilege access controls for system and application accounts
- Deploy monitoring for privilege escalation attempts and unauthorized process spawning
- Test patches in isolated environment before deploying to production systems
References
- https://github.com/xkalami-Tta0/CVE/blob/main/Intern%20Membership%20Management%20System/Intern%20Membership%20Management%20System%20delete_activity.php%20sql%20injection.md
- https://vuldb.com/?id.340445
- https://vuldb.com/?submit.733486
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-083-03.json
- https://www.se.com/en/en/work/support/security-center
- https://nvd.nist.gov/vuln/detail/CVE-2026-0850
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 5 of March 2026 (March 30 – April 5)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.