Vulnerability Description
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-Syste
- https://github.com/qflksheep/ICS-Park-Smart-Park-Management-System-v2.0-POC/blob
- https://github.com/qflksheep/ICS-Park-Smart-Park-Management-System-v2.0-POC/blob
FAQ
What is CVE-2026-67687?
CVE-2026-67687 is a vulnerability with a CVSS score of 8.8 (HIGH). Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserCo...
How severe is CVE-2026-67687?
CVE-2026-67687 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67687?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.