CVE-2026-67688
Received Received - Intake

Unrestricted File Upload in ICS-Park Smart Park Management System

Vulnerability report for CVE-2026-67688, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: MITRE

Description

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ICS-Park Smart Park Management System v2.0 has an unrestricted file upload vulnerability in its file upload module. This flaw allows a remote attacker to upload malicious files without restrictions, potentially leading to arbitrary code execution on the affected system.

Detection Guidance

Detecting unrestricted file upload vulnerabilities typically involves checking file upload endpoints for improper validation. Inspect network traffic for unexpected file types or large uploads. Review server logs for unusual file extensions or paths. Test with various file types including .php, .jsp, or .exe to see if they are accepted.

Impact Analysis

This vulnerability could allow attackers to upload and execute malicious files on your system. This may lead to unauthorized access, data breaches, system compromise, or further network infiltration if the system is part of a larger infrastructure.

Mitigation Strategies

Immediately restrict file uploads to specific directories with strict permissions. Implement strict file type and extension validation. Use allowlists for permitted file types. Ensure uploaded files are stored outside the web root and cannot be executed. Regularly audit uploaded files and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67688. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart