CVE-2026-67687
HIGH 8.8EPSS 0.4%
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.45% chance of exploitation in the next 30 days, 38th percentile
- Published
- 2026-08-06
- Updated
- 2026-08-07
Proof-of-concept exploits (2)
- qflksheep/ICS-Park-Smart-Park-Management-System-v2.0-POC/blob/main/poc
- qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.00★ · 2026-08-05