CVE-2026-67688 is an unrestricted file upload vulnerability in the file upload module of ICS-Park Smart Park Management System v2.0. The flaw allows an attacker to upload a file of a type or content that is not adequately restricted or validated by the application. If the uploaded file is accepted and subsequently processed or executed by the server, the issue can be leveraged to achieve arbitrary code execution on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains two text/markdown-style PoC writeups rather than executable exploit code. Both target ICS-Park Smart Park Management System v2.0, apparently built on the RuoYi framework. There are only two files, each documenting a separate authenticated web vulnerability with step-by-step HTTP requests and expected responses. CVE-2026-67687 describes a vertical privilege-escalation chain. The core capability is that any authenticated ordinary user can create a new role with arbitrary permissions via /system/role/save because authorization is missing, then use /system/user/update to assign that role to their own account because the default low-privilege role still has system:user:edit. After re-authentication, the attacker gains elevated permissions such as system:user:add and can create additional administrator accounts through /system/user/save. This is a true exploit chain, though presented as manual HTTP PoC steps rather than automation. It provides persistent privileged access and could support further compromise. CVE-2026-67688 documents unrestricted HTML upload leading to stored XSS. Any authenticated user can upload an .html file through /dfs/upload, and the returned file is served from a static /profile/... path under the application origin. The payload examples include simple cookie alerting and exfiltration to attacker.com. The exploit capability is arbitrary JavaScript execution in the browser context of users who open the uploaded file, enabling session theft, phishing, and abuse of administrator sessions. Repository structure is minimal: two standalone advisory/PoC files, no scripts, no framework metadata, and no automation. Because there is no runnable code, the maturity is best classified as POC. The main fingerprintable targets are the application endpoints /auth/login, /system/role/save, /system/user/update, /system/user/save, /system/user/info, /dfs/upload, and the static uploaded-file path under /profile/. The content also references localhost:9227 as an example deployment host and attacker.com as an example exfiltration domain.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.