CVE-2026-10243
📛 CVE Title
code-projects Smart Parking System Admin Endpoint missing authentication
Description
A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulDB
- CVSS severity
- MEDIUM
- CVSS score
- 6.9 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P- Effective score
- 6.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-306,CWE-287 - Reserved
- 2026-05-31
- Published
- 2026-06-01 09:00 UTC
- Last updated
- 2026-06-01 15:23 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/10xxx/CVE-2026-10243.json
- Linked Threat
- CVE-2026-10243 — CVE-2026-10243
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-01 09:16:16 UTC
- NVD last modified
- 2026-07-22 07:10:00 UTC
- NVD CVSS v3.1
- 7.3 / 10 HIGH source: cna@vuldb.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.4 / 10
- EPSS score
- 0.0063 (probability of exploitation in next 30 days)
- EPSS percentile
- 46.45% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27
NVD / KEV / EPSS data refreshed 2026-07-27 21:06 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-33608 - Assigner
- VulDB
- Published
- Jun 1, 2026, 9:00:13 AM
- Updated
- Jun 1, 2026, 3:23:18 PM
- EUVD base score (CVSS 4.0)
-
6.9 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P - EUVD-reported EPSS
- 0.6300
- Vendors
- code-projects
- Products
-
Smart Parking System (1.0)
- Aliases
-
GHSA-p963-jch7-x2f5
ENISA description: A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| code-projects | Smart Parking System |
1.0 (affected)
|
— |
Vendor references (6)
References embedded in the original CVE record by the assigning CNA.
- VDB-367521 | code-projects Smart Parking System Admin Endpoint missing authentication vdb-entry
- VDB-367521 | CTI Indicators (IOB, IOC) signaturepermissions-required
- CVE-2026-10243 | CVE Analysis and Report third-party-advisory
- Submit #823871 | code-projects Smart Parking System In PHP With Source Code 1.0 Improper Access Controls third-party-advisory
- https://github.com/Xmyronn/smart-parking-system-broken-access.git exploit
- https://code-projects.org/ product
Web references (9)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://code-projects.org/ tenable:code-projects.org
- https://github.com/Xmyronn/smart-parking-system-broken-access.git tenable:github.com
- https://nvd.nist.gov/vuln/detail/CVE-2026-10243 tenable:nvd.nist.gov
- https://vuldb.com/cve/CVE-2026-10243 tenable:vuldb.com
- https://vuldb.com/submit/823871 tenable:vuldb.com
- https://vuldb.com/vuln/367521 tenable:vuldb.com
- https://vuldb.com/vuln/367521/cti tenable:vuldb.com
- https://www.cve.org/CVERecord?id=CVE-2026-10243 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (6)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://code-projects.org/ cna@vuldb.com
- https://github.com/Xmyronn/smart-parking-system-broken-access.git cna@vuldb.com
- https://vuldb.com/cve/CVE-2026-10243 cna@vuldb.com
- https://vuldb.com/submit/823871 cna@vuldb.com
- https://vuldb.com/vuln/367521 cna@vuldb.com
- https://vuldb.com/vuln/367521/cti cna@vuldb.com
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-08 16:01 UTC -
web:nvd.nist.gov
Description Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command ...
2026-06-08 16:01 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-08 16:01 UTC -
web:support.apple.com
This document describes the content of Background Security Improvements.
2026-06-08 16:01 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-06-08 16:01 UTC -
web:www.cisecurity.org
<p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...
2026-06-08 16:01 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-06-08 16:01 UTC -
web:www.helpnetsecurity.com
Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE -numbered vulnerabilities, none of which are actively exploited.
2026-06-08 16:01 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-08 16:01 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-08 16:01 UTC -
web:blog.talosintelligence.com
Microsoft has released its monthly security update for February 2026 , which includes 55 vulnerabilities affecting a range of products, including one ( CVE -2025-59498) that Microsoft marked as "Critical".
2026-06-19 02:32 UTC -
web:blogs.oracle.com
For more information about the Critical Security Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.
2026-06-19 02:32 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:32 UTC -
web:fixtrading.org
The FIX Trading Community is the independent, non‑profit, industry‑driven standards body at the heart of global trading, and the custodian of the FIX Protocol—the world's leading standard for real‑time electronic trading.
2026-06-19 02:32 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:32 UTC -
web:techcommunity.microsoft.com
UPDATE June 9, 2026 : Please see our release blog post for June 2026 Security Update for more information on this CVE : Released: June 2026 Exchange Server Security Updates | Microsoft Community Hub. On May 14, 2026 , Microsoft disclosed CVE - 2026 -42897, a reported vulnerability affecting Exchange Outlook Web Access (OWA). An attacker could exploit this issue by sending a specially crafted email ...
2026-06-19 02:32 UTC -
web:vulners.com
CVE-2026-10243 affects the Smart Parking System Admin Endpoint with missing authentication, enabling remote exploitation.
2026-06-19 02:32 UTC -
web:www.linkedin.com
Microsoft has confirmed that it is developing a security update to address a newly disclosed zero-day vulnerability in Microsoft Defender, following the public release of exploit code that ...
2026-06-19 02:32 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:32 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - January 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical ...
2026-06-19 02:32 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-10243.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-10243",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-01T15:00:26.860506Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-01T15:23:18.984Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:code-projects:smart_parking_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Admin Endpoint"
],
"product": "Smart Parking System",
"vendor": "code-projects",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "imad alvi (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-01T09:00:13.192Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-367521 | code-projects Smart Parking System Admin Endpoint missing authentication",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/367521"
},
{
"name": "VDB-367521 | CTI Indicators (IOB, IOC)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/367521/cti"
},
{
"name": "CVE-2026-10243 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-10243"
},
{
"name": "Submit #823871 | code-projects Smart Parking System In PHP With Source Code 1.0 Improper Access Controls",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/823871"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/Xmyronn/smart-parking-system-broken-access.git"
},
{
"tags": [
"product"
],
"url": "https://code-projects.org/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-05-31T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-05-31T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-05-31T12:17:08.000Z",
"value": "VulDB entry last update"
}
],
"title": "code-projects Smart Parking System Admin Endpoint missing authentication"
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-10243",
"datePublished": "2026-06-01T09:00:13.192Z",
"dateReserved": "2026-05-31T10:12:00.665Z",
"dateUpdated": "2026-06-01T15:23:18.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}