A vulnerability marked as critical has been reported in MRCMS 3.1.2 . This affects the function Save of the file src/main/java/org/marker/mushroom/controller/UserController.java . This manipulation causes improper access controls. This vulnerability is handled as CVE-2026-31272 . The attack can be initiated remotely. There is not any exploit available.