Description
A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Authorization leading to unauthorized access
Action: Apply Patch
AI Analysis

Impact

A flaw in the AuthorizationInterceptor.java component of the Tourism-Management-System allows an attacker to bypass normal authorization checks. The weakness permits an attacker to gain privileges beyond those assigned to the user, potentially accessing sensitive data or performing privileged actions. The vulnerability is considered moderate with a CVSS score of 5.3 and has been publicly disclosed, meaning exploitation code is available.

Affected Systems

The affected product is the Tourism-Management-System released by Jaychouchannel. All versions up to the commit hash 84d8ec384f669df3985293dab293bb7b477efa64 are vulnerable. The project follows a rolling release model, so no fixed version list exists; the patch with hash d984d172dceca907f8b447efbdb06dc233f7938d addresses the issue.

Risk and Exploitability

The CVSS of 5.3 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation, but public disclosure means exploitation code is available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; an attacker could target the system through its web interface or APIs to exploit the improper authorization logic, enabling unauthorized actions.

Generated by OpenCVE AI on September 15, 2026 at 16:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the public patch identified by commit d984d172dceca907f8b447efbdb06dc233f7938d to the AuthorizationInterceptor.java file
  • Review and tighten role validation logic in the AuthorizationInterceptor to enforce strict access control
  • Revoke or re‑issue credentials for any accounts that may have been compromised during the vulnerability window
  • Validate that the updated system correctly distinguishes user roles and limits actions accordingly
  • Configure monitoring on authentication and authorization events to detect future attempts to bypass controls

Generated by OpenCVE AI on September 15, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Title jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization
First Time appeared Jaychouchannel
Jaychouchannel tourism-management-system
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
Vendors & Products Jaychouchannel
Jaychouchannel tourism-management-system
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jaychouchannel Tourism-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T00:35:31.442Z

Reserved: 2026-09-12T10:54:50.270Z

Link: CVE-2026-90520

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:52.316Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T13:16:28.760

Modified: 2026-09-20T01:16:32.397

Link: CVE-2026-90520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization