Description
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Privilege Management
Action: Apply Patch
AI Analysis

Impact

A flaw in the User Register endpoint causes improper privilege management. The flaw originates from insufficient validation of the UsersEntity argument in UsersController.java, enabling an attacker to set privilege levels that should not be granted. This vulnerability is related to CWE-266 and CWE-269 and allows unauthorized users to gain elevated privileges within the application. Based on the description, it is inferred that such privilege controls.

Affected Systems

The affected product is jaychouchannel Tourism-Management-System, particularly the User Register endpoint implemented in UsersController.java. Because the project does not specify version numbers, all releases up to the patch commit 84d8ec384f669df3985293dab293bb7b477efa64 are considered vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is below 1%, indicating a low but non‑zero probability of exploitation. The exploit is described as publicly available and can be triggered remotely. The lack of a KEV listing does not eliminate the need for remediation, as the identified flaw permits direct privilege escalation that an attacker with internet access could exploit. The attack requires only the ability to send a crafted UsersEntity payload to the registration endpoint, making it a feasible remote attack vector.

Generated by OpenCVE AI on September 15, 2026 at 16:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch corresponding to commit 84d8ec384f669df3985293dab293bb7b477efa64 to update UsersController.java and redeploy the application.
  • Ensure that all privilege checks for the UsersEntity input enforce the intended access controls, especially around role assignment.
  • Conduct targeted penetration tests against the user registration endpoint to confirm that privilege escalation is no longer possible.

Generated by OpenCVE AI on September 15, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Title jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management
First Time appeared Jaychouchannel
Jaychouchannel tourism-management-system
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
Vendors & Products Jaychouchannel
Jaychouchannel tourism-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jaychouchannel Tourism-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:29:01.108Z

Reserved: 2026-09-12T10:55:01.371Z

Link: CVE-2026-90523

cve-icon Vulnrichment

Updated: 2026-09-14T15:28:57.446Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T14:16:49.337

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management