CVE-2026-107702: QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an idhotel parameter. Attackers can modify the idhotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated back-office employee with restricted access can exploit it. The attacker needs access to the Admin Room Booking “Book Now” page and can alter its id_hotel URL parameter.
What information can be accessed?
A restricted employee can view room availability and booking status for hotels outside the hotels assigned to that employee's profile access.
Are deployments affected by default?
The issue is described in QloApps through version 1.7.0 and affects the Admin Room Booking controller's handling of the id_hotel parameter. Exploitation requires a restricted back-office account rather than unauthenticated access.
How can administrators identify possible exploitation?
Review requests to the Admin Room Booking Book Now page for id_hotel values that do not correspond to the authenticated employee's assigned hotel access. Access to availability or booking-status data for unassigned hotels is indicative of misuse.