Junglewise Threat Intelligence

CVE-2026-36723: BookCars unrestricted file rename in /api/create-user component

CVE-2026-36723 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: BookCars. Vendors: BookCars.

Executive brief

BookCars, a car rental management system, contains a security flaw in its user creation component. An authenticated user can exploit this to move and rename files on the server, potentially leading to a full system takeover. This could result in the theft of customer data, service disruption, or the installation of malicious software on the company's infrastructure.

Technical details

An unrestricted file rename vulnerability exists in the /api/create-user endpoint of BookCars v8.3, specifically within the userRoutes.ts and userController.ts components. Authenticated attackers can utilize directory traversal sequences (e.g., ../) to move files from temporary storage to arbitrary locations on the server's filesystem. This flaw allows for the overwriting of critical application files or the placement of malicious scripts in web-accessible directories. Successful exploitation can lead to unauthorized access to sensitive data, persistent system compromise, and remote code execution (RCE).

Affected products

  • BookCars BookCars 8.3

Timeline

  • 2026-06-09: disclosed: Initial vulnerability disclosure and CVE assignment.
  • 2026-06-09: advisory: NVD published the vulnerability details.

References

Related threats