CVE-2026-90522: jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery

Published Sep 13, 2026
·
Updated

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.

Affected Software

1 affected component
jaychouchannel Tourism-Management-System - Password Recovery (UsersController.java resetPass)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade jaychouchannel Tourism-Management-System (Password Recovery / UsersController.java resetPass) to a version that resolves this vulnerability.

    Patch 9cb6215ac871f99a90cde763cf003e95ff282283

Event History

Sep 13, 2026
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

The issue can be initiated remotely and requires no privileges or user interaction, according to the supplied severity vector. Systems exposing the affected password-recovery functionality are therefore the relevant attack surface.

2

Is a public exploit available?

Yes. The exploit has been publicly disclosed and may be used.

3

Which releases are affected or fixed?

The affected code is reported through commit d984d172dceca907f8b447efbdb06dc233f7938d. Because the product uses continuous delivery with rolling releases, no affected or fixed version numbers are available; the identified patch is 9cb6215ac871f99a90cde763cf003e95ff282283.

4

What should teams do if they cannot immediately confirm a version number?

Compare the deployed source or build provenance with the identified patch and apply patch 9cb6215ac871f99a90cde763cf003e95ff282283. Version-based verification is not available for this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203