CVE-2026-105836: QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the idrooms parameter to change status, floor, comments, or inactive dates, disrupting availability and bookings.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A back-office employee account that is restricted to a particular hotel can exploit it. The attacker must be able to access the bulk room update functionality and submit room IDs belonging to another hotel.
What can an attacker change using this bypass?
An attacker can change the status, floor, comments, or inactive dates of rooms assigned to other hotels. These changes can disrupt room availability and bookings.
Are unauthenticated users affected?
No. The provided vector requires low privileges, and the described attack requires a hotel-restricted back-office employee account.
How can administrators identify possible exploitation?
Review changes to room status, floor, comments, and inactive dates for rooms belonging to a hotel other than the account holder's assigned hotel. The relevant request uses the id_rooms parameter to supply room identifiers.