Junglewise Threat Intelligence

CVE-2026-10693: SourceCodester Online Boat Reservation System improper authorization

CVE-2026-10693 · Severity: medium · CVSS 6.3 · Published 2026-06-03

Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Boat Reservation System, a platform used for managing boat rentals and bookings. An attacker with basic user access can bypass intended security restrictions to access administrative functions. This could allow unauthorized individuals to view or modify reservation data, potentially disrupting business operations and compromising customer information.

Technical details

A broken access control vulnerability (CWE-285/CWE-266) exists in SourceCodester Online Boat Reservation System 1.0. The flaw is located within the Administrative Endpoint component, where insufficient authorization checks allow authenticated users with low-level privileges to perform actions intended for administrators. An attacker can exploit this remotely by manipulating requests to multiple affected endpoints. Successful exploitation could lead to unauthorized data access or modification. The exploit has been disclosed publicly, but no official patch is currently documented.

Affected products

  • SourceCodester Online Boat Reservation System 1.0

Timeline

  • 2026-06-03: advisory: Vulnerability published by NVD/VulDB
  • 2026-06-03: disclosed: Public exploit disclosed via Medium/VulDB

References

Related threats