CVE-2026-90523: jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management

Published Sep 13, 2026
·
Updated

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.

Affected Software

1 affected component
jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade User Register Endpoint (travel/src/main/java/com/controller/UsersController.java) to a version that resolves this vulnerability.

    Patch 84d8ec384f669df3985293dab293bb7b477efa64

Event History

Sep 13, 2026
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Feb 2, 58671
Event
via NVD·06:57 PM

Frequently Asked Questions

1

Who can exploit this issue?

The issue can be exploited remotely and requires no privileges or user interaction. An attacker can manipulate the UsersEntity argument handled by the user registration endpoint.

2

Are publicly exposed deployments at greater risk?

Yes. Because exploitation is remote, low complexity, and requires no authentication, any deployment where the user registration endpoint is reachable by an attacker may be exposed. Public exploit availability increases the likelihood of attempted exploitation.

3

Which releases are affected?

Affected and unaffected releases cannot be identified by version because the product does not use versioning. The vulnerable code is identified as being present up to commit 229956e20dbd4a80eeff14535e44d3099502af09.

4

What should be done to remediate the issue?

Apply patch commit 84d8ec384f669df3985293dab293bb7b477efa64. If patching cannot happen immediately, restrict access to the user registration endpoint to trusted users or networks where feasible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203