CVE-2026-107702: QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking

Published Oct 8, 2026
·
Updated

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an idhotel parameter. Attackers can modify the idhotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.

Affected Software

1 affected component
QloApps QloApps<=1.7.0

Event History

Oct 8, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated back-office employee with restricted access can exploit it. The attacker needs access to the Admin Room Booking “Book Now” page and can alter its id_hotel URL parameter.

2

What information can be accessed?

A restricted employee can view room availability and booking status for hotels outside the hotels assigned to that employee's profile access.

3

Are deployments affected by default?

The issue is described in QloApps through version 1.7.0 and affects the Admin Room Booking controller's handling of the id_hotel parameter. Exploitation requires a restricted back-office account rather than unauthenticated access.

4

How can administrators identify possible exploitation?

Review requests to the Admin Room Booking Book Now page for id_hotel values that do not correspond to the authenticated employee's assigned hotel access. Access to availability or booking-status data for unassigned hotels is indicative of misuse.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203