Description
An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.
Published: 2026-06-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to delete any file on the server by exploiting directory traversal sequences in the /api/delete-temp-license/{file} endpoint, enabling arbitrary file deletion and disrupting service integrity and availability.

Affected Systems

The affected software is bookcars version 8.3; vendor information is not specified, and no other versions are confirmed to be vulnerable based on the current data.

Risk and Exploitability

Because the endpoint is accessible without authentication, an attacker can remotely trigger deletions, posing a high risk to system availability and data integrity; the absence of EPSS and KEV data suggests a moderate to high potential, but formal severity metrics are not provided.

Generated by OpenCVE AI on June 9, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a non‑vulnerable version of bookcars if available
  • Restrict access to the /api/delete-temp-license/{file} endpoint to authenticated and authorized users only
  • Implement strict validation or sanitization of file path inputs to eliminate directory traversal vulnerabilities

Generated by OpenCVE AI on June 9, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Bookcars
Bookcars bookcars
Vendors & Products Bookcars
Bookcars bookcars

Tue, 09 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Arbitrary File Deletion via Directory Traversal in bookcars API
Weaknesses CWE-20
CWE-22

Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.
References

Subscriptions

Bookcars Bookcars
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T18:13:18.455Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36726

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:43.093

Modified: 2026-06-09T19:35:05.693

Link: CVE-2026-36726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T11:23:13Z

Weaknesses