Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Privilege Escalation via Insecure Permissions in Park Smart Park Management System v.2.0 | |
| Weaknesses | CWE-284 CWE-732 |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-06T19:56:52.599Z
Reserved: 2026-07-30T00:00:00.000Z
Link: CVE-2026-67687
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:30:04Z