Sceawere

Vulnerability Detail

CVE-2026-90520UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Authorization in Tourism-Management-System

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
jaychouchannel
Product
Tourism-Management-System
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-13T13:16:28.760Z",
  "pubdate": "2026-09-13T13:16:28.760Z",
  "executiveSummary": "A critical improper authorization vulnerability has been identified within the Tourism-Management-System, specifically impacting the AuthorizationInterceptor.java component. This vulnerability allows remote, unauthenticated, or unauthorized actors to bypass security controls implemented within the application's interceptor logic.\nThe flaw stems from a failure to correctly validate access rights during the request lifecycle. By exploiting this weakness, an attacker can perform actions or access resources that should be restricted to authorized users, leading to potential unauthorized data access, modification, or administrative privilege escalation.\nThe vulnerability is present in the codebase up to commit 84d8ec384f669df3985293dab293bb7b477efa64. Given that the product utilizes a rolling release model, users are at persistent risk until the specific patch is applied. The exploit for this vulnerability is publicly disclosed, significantly increasing the risk of active exploitation by threat actors.\nThe vulnerability requires no special authentication to initiate, making it a high-risk entry point for remote attackers aiming to compromise the integrity and confidentiality of the management system.",
  "technicalDetails": "The vulnerability resides within AuthorizationInterceptor.java, a core component responsible for enforcing security policies before requests reach the application controllers. In the affected versions, the interceptor fails to correctly verify authorization credentials or session states, resulting in a flawed enforcement mechanism that permits requests to bypass required permission checks.\nThe root cause is identified as an insufficient validation logic within the pre-handle request flow. When a request is intercepted, the code does not perform a strict check against the current security context or the intended resource's security requirements. This allows an attacker to access protected endpoints simply by interacting with the application, as the interceptor inadvertently permits the request to proceed to the controller level.\nThe attack flow begins with a remote attacker identifying an endpoint protected by the AuthorizationInterceptor. By crafting a request that would normally be blocked due to lack of privileges, the attacker exploits the flawed logic in AuthorizationInterceptor.java. Because the interceptor fails to terminate the request lifecycle upon detecting missing or invalid authorization tokens, the application proceeds to execute the requested business logic or data retrieval operation as if the user possessed legitimate credentials.\nBecause the system uses a rolling release, there is no fixed version number; the vulnerability affects all deployments prior to the application of patch d984d172dceca907f8b447efbdb06dc233f7938d. The vulnerability is network-accessible, meaning an attacker can trigger the unauthorized state from any external network reach.\nThe post-exploitation impact includes unauthorized data exfiltration, modification of database records, and the potential for full administrative takeover depending on the exposed functionality of the underlying controllers. Since the exploit is already public, attackers may automate the scanning and exploitation of this flaw, making it a high-priority incident for administrators managing instances of the Tourism-Management-System."
}
CVE-2026-90520: Improper Authorization in Tourism-Management-System (MEDIUM Severity, CVSS: 6.3) | Sceawere