SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86284

MEDIUM · CVSS 5.3 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Tourism Management System in Java is vulnerable due to improper handling of the `tableName/columnName` arguments in the `getOption` function, which can lead to information disclosure. This vulnerability can be exploited remotely, potentially exposing sensitive data. Organizations using affected versions of this system should prioritize applying the provided patch to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86284
Severity
MEDIUM
CVSS
5.3
EPSS
0.32%
Java

Original NVD Description

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.