Description
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical update functionality
Action: Patch Now
AI Analysis

Impact

The checks, allowing remote attackers to manipulate the component. The missing authentication bypass defeats the system’s security controls, exposing the application to unauthorized modifications. The weakness is characterized by CWE-287 and CWE-306, both indicating insufficient or missing authentication safeguards. Consequently, an attacker could change system data, introduce malicious code, tourism management system, compromising confidentiality, integrity, and availability for users and administrators.

Affected Systems

The affected product is jaychouchannel Tourism-Management-System, as identified by the CNA vendor/product string. No specific version numbers can be pinpointed because the project follows a rolling‑release model, but all releases up to commit 229956e20dbd4a80eeff14535e44d3099502af09 are impacted. The discovered patch carries the hash 84d8ec384f669df3985293dab293bb7b477efa64 and addresses the authentication flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity, while the EPSS score is 0.00693 (<1%). The vulnerability is not listed in the CISA KEV catalog, yet the exploit is publicly available and can be launched remotely. Based on the description, it is inferred that attackers may not need special credentials to exploit the unprotected Update endpoint; the lack of authentication checks suggests remote exploitation is feasible without local access. Given the combination of remote impact, moderate CVSS, and public exploit code, the overall threat level warrants timely action.

Generated by OpenCVE AI on September 15, 2026 at 16:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 84d8ec384f669df3985293dab293bb7b477efa64 to the Tourism-Management-System repository
  • Restrict authentication until the patch is applied
  • Review and harden the authentication mechanisms for all exposed endpoints to prevent future omissions

Generated by OpenCVE AI on September 15, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.
Title jaychouchannel Tourism-Management-System Update Endpoint missing authentication
First Time appeared Jaychouchannel
Jaychouchannel tourism-management-system
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
Vendors & Products Jaychouchannel
Jaychouchannel tourism-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jaychouchannel Tourism-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:55.844Z

Reserved: 2026-09-12T10:55:04.755Z

Link: CVE-2026-90524

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:34.274Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T14:16:50.340

Modified: 2026-09-15T15:17:28.233

Link: CVE-2026-90524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function