CyberRota
Back to database

CVE-2026-6375

UNKNOWN · CVSS N/A EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published: 2026-04-23 · Last synced: 2026-05-23

CyberRota Analysis

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-6375
Severity
UNKNOWN
CVSS
N/A
EPSS
0.07%

Original NVD Description

A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.