Junglewise Threat Intelligence

CVE-2026-10236: SourceCodester Water Billing Management System improper authorization in Users.php

CVE-2026-10236 · Severity: high · CVSS 7.3 · Published 2026-06-01

Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Water Billing Management System, a software used to manage utility billing and customer records. An unauthorized person can remotely bypass security checks to perform administrative actions, such as creating new user accounts. This could allow an attacker to take control of the system, access customer data, or disrupt billing operations.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in SourceCodester Water Billing Management System 1.0 within the '/classes/Users.php?f=save' endpoint. The component responsible for user management fails to properly validate the authorization level of the requester. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the endpoint to create a new administrator account. This vulnerability has been publicly disclosed with proof-of-concept details available, though no official patch is currently documented.

Affected products

  • SourceCodester Water Billing Management System 1.0

Timeline

  • 2026-06-01: advisory: Vulnerability published by VulDB and NVD
  • 2026-06-01: disclosed: Exploit details disclosed to the public

References

Related threats