CVE-2026-10236
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file
CVSS
7.3
Alto
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-266 · CWE-285
0.4%EPSS · 30 días0.4%
2026-08-222026-09-19
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
- github.comhttps://github.com/renzortega1337/Security-Research-/blob/main/Unauthenticated%20Admin%20Creation%20in%20PHP%20System.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10236
- vuldb.comhttps://vuldb.com/submit/823134
- vuldb.comhttps://vuldb.com/vuln/367515
- vuldb.comhttps://vuldb.com/vuln/367515/cti
- www.sourcecodester.comhttps://www.sourcecodester.com/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-939554.3 MED—
———A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.3hCVE-2026-939544.3 MED—
———A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.4hCVE-2026-842418.1 ALT22.8%
——7IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.12hCVE-2026-840767.6 ALT23.9%
——7IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.11hCVE-2026-840367.4 ALT17.6%
——5IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.11hCVE-2026-772398.1 ALT21.2%
——6WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypasses row-level security. In src/app/api/flows/[id]/route.ts, src/app/api/flows/[id]/activate/route.ts, and src/app/api/flows/route.ts, a viewer can create, edit, activate, or delete flows because membership-only checks are followed by service-role writes. In src/app/api/automations/route.ts and src/app/api/automations/engine/route.ts, a viewer can create active automations and trigger outbound WhatsApp actions without the role required by the underlying write policies. This can permit unauthorized workflow changes, destructive flow deletion, and outbound actions from a role intended to be read-only. This vulnerability is fixed with commit 03e851bea56dcf6bb21ff1b80ba531372bf3269f.1d