CVE-2026-90523: jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
User Register Endpoint (travel/src/main/java/com/controller/UsersController.java)to a version that resolves this vulnerability.Patch 84d8ec384f669df3985293dab293bb7b477efa64
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue can be exploited remotely and requires no privileges or user interaction. An attacker can manipulate the UsersEntity argument handled by the user registration endpoint.
Are publicly exposed deployments at greater risk?
Yes. Because exploitation is remote, low complexity, and requires no authentication, any deployment where the user registration endpoint is reachable by an attacker may be exposed. Public exploit availability increases the likelihood of attempted exploitation.
Which releases are affected?
Affected and unaffected releases cannot be identified by version because the product does not use versioning. The vulnerable code is identified as being present up to commit 229956e20dbd4a80eeff14535e44d3099502af09.
What should be done to remediate the issue?
Apply patch commit 84d8ec384f669df3985293dab293bb7b477efa64. If patching cannot happen immediately, restrict access to the user registration endpoint to trusted users or networks where feasible.