CVE-2026-36720

HIGH

bookcars 8.3 - Authenticated Privilege Escalation via User Type Modification

Title source: llm
STIX 2.1

Description

Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.

Scores

CVSS v3 8.1
EPSS 0.0025
EPSS Percentile 15.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Published Jun 09, 2026
Tracked Since Jun 10, 2026