June 22, 2026

When Anyone Can Be Admin: The Boat Booking App That Left the Back Door Wide Open

A breakdown of CVE-2026–10693 — a real-world authorization flaw that let regular users do administrator things

Agonize

2 min read