SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90523

HIGH · CVSS 7.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability affects the User Register Endpoint in the Tourism-Management-System, specifically within the UsersController.java file, leading to improper privilege management due to manipulation of the UsersEntity argument. This high-severity flaw can be exploited remotely, with publicly available exploits, making it critical for organizations using this Java-based system to prioritize patching with the provided fix. Immediate action is recommended to mitigate potential unauthorized access and privilege escalation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90523
Severity
HIGH
CVSS
7.3
EPSS
N/A
Java

Original NVD Description

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.