Sceawere
Vulnerability Detail
CVE-2026-90524UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Authentication Bypass in Tourism-Management-System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- jaychouchannel
- Product
- Tourism-Management-System
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-13T14:16:50.340Z",
"pubdate": "2026-09-13T14:16:50.340Z",
"executiveSummary": "A critical security vulnerability identified as missing authentication has been discovered in the jaychouchannel Tourism-Management-System, affecting versions up to 229956e20dbd4a80eeff14535e44d3099502af09.\nThe vulnerability resides within the Update Endpoint component, allowing unauthenticated remote attackers to perform unauthorized actions due to improper access control.\nThis flaw presents a significant risk, as it permits interaction with restricted system functions without requiring valid credentials. Because the exploit has been released to the public, the potential for malicious utilization is high.\nThe system's rolling release model complicates version tracking; however, the vulnerability is addressed by a specific patch. Immediate application of the identified fix is required to restore access control integrity and prevent unauthorized remote exploitation.",
"technicalDetails": "The vulnerability is characterized as an authentication bypass resulting from the failure to implement or enforce access control checks within the Update Endpoint component of the jaychouchannel Tourism-Management-System.\nRoot Cause Analysis: The underlying defect exists within the request handling logic of the Update Endpoint. In a secure implementation, this endpoint would be required to validate the session token, API key, or authentication cookie of the requesting party before executing the requested update operations. The vulnerable implementation fails to perform these checks, treating incoming HTTP requests as trusted regardless of the source or authorization status.\nExploitation Method: An attacker can exploit this flaw by sending a crafted HTTP request directly to the vulnerable Update Endpoint. Since the component performs no authentication verification, the application processes the request as if it originated from an authorized administrative user. The attack can be initiated remotely over the network, requiring no prior authentication or specific privilege level on the target system.\nAttack Flow: 1. The attacker identifies the URI associated with the Update Endpoint. 2. The attacker constructs a malicious payload containing the necessary parameters to manipulate the system state or data. 3. The attacker transmits the request to the target server via standard HTTP methods (e.g., POST or PUT). 4. The application receives the request, bypasses the non-existent authentication logic, and executes the requested update action with the privileges of the system application user.\nPost-Exploitation Impact: Successful exploitation permits remote, unauthenticated actors to modify system configurations, update or alter application data, and potentially escalate their presence within the environment depending on the specific functionality exposed by the Update Endpoint. Given the public availability of the exploit, the barrier to entry for attackers is significantly lowered, increasing the probability of successful exploitation in production environments. Because this product uses a rolling release model, any deployment utilizing the codebase prior to the application of patch 84d8ec384f669df3985293dab293bb7b477efa64 remains susceptible."
}