CVE-2026-67687
HIGHICS-Park Smart Park Management System 2.0 - Unauthenticated Privilege Escalation via Role and User Controller Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-67687. PoCs published by qflksheep.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2026-67687, a vertical privilege escalation vulnerability in ICS-Park Smart Park Management System v2.0. The PoC demonstrates how an ordinary user can create an administrator account by exploiting missing authorization checks in the RoleController.save() and UserController.update() endpoints.
Description
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
Exploits (1)
The repository contains functional exploit code for CVE-2026-67687, a vertical privilege escalation vulnerability in ICS-Park Smart Park Management System v2.0. The PoC demonstrates how an ordinary user can create an administrator account by exploiting missing authorization checks in the RoleController.save() and UserController.update() endpoints.
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H