Junglewise Threat Intelligence

CVE-2026-10876: SourceCodester Ship Ferry Ticket Reservation System improper authorization in admin

CVE-2026-10876 · Severity: medium · CVSS 6.3 · Published 2026-06-05

Technologies: SourceCodester Ship Ferry Ticket Reservation System. Vendors: SourceCodester.

Executive brief

A security flaw has been found in the SourceCodester Ship Ferry Ticket Reservation System, a web application used for managing ferry bookings. This vulnerability allows an attacker to bypass security checks and access administrative functions or data they should not be able to see. This could lead to unauthorized changes to ticket records or exposure of sensitive reservation information.

Technical details

A vulnerability exists in SourceCodester Ship Ferry Ticket Reservation System 1.0 due to improper authorization (CWE-285) within the /admin/ directory. The flaw is triggered by manipulating the 'page' argument, which allows an authenticated user with low privileges to access administrative functions or restricted pages. An attacker can exploit this over the network to view or modify data without proper permission. Public exploit code has been released for this vulnerability. No official patch has been confirmed at this time.

Affected products

  • SourceCodester Ship Ferry Ticket Reservation System 1.0

Timeline

  • 2026-06-05: disclosed: Vulnerability published to NVD

References

Related threats