• News/
  • https://www.darkreading.com/application-security/oauth-flaw-exposed-millions-airline-users-account-takeovers

OAuth Flaw Exposed Millions of Airline Users to Account Takeovers

Dark Reading
·
Jai Vijayan
·
Published Jan 28, 2025
·
Updated

A vulnerability that exposed millions of airline customers to potential account takeovers has highlighted the significant risks organizations face from misconfigured OAuth authentication processes. The vulnerability in this case involved a major provider of online travel services for hotels and car rentals. Many airlines have integrated this service into their websites, allowing customers to use their airline points to book not just flights, but also hotels and rental cars in one seamless process. Researchers at Salt Security, hunting for real-world examples of API supply chain attacks, stumbled upon a vulnerability in the travel company's process for authenticating users looking to access its services after making an initial airline booking. The flaw, which the travel services company has since fixed, basically gave attackers a way to redirect a user's OAuth credentials to a server of their choice. The credentials would have allowed the attackers to obtain a valid session token from an airline's website and use it to log into the travel company's systems as the victim and book hotels and car rentals using airline loyalty points. The discovered vulnerability enabled attackers to hijack victim accounts with a single click, Salt Security researcher Amit Elbirt wrote in a blog post this week, without revealing the identity of the travel services company. While the takeover would have happened within the travel provider's service, it would have given an attacker full access to a ...

Read full article

Affected Software

5 affected components
Booking.com online travel service
Grammarly authentication system
Vidio authentication system
Bukalapak e-commerce site
Major Provider Online Travel Services
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in OAuth authentication that exposed millions of airline users to account takeover risks.

2

What security implications are discussed in the article?

The article highlights the risks associated with misconfigured OAuth authentication processes that can lead to unauthorized access.

3

What products or software are affected by this vulnerability?

The affected products include Booking.com, Grammarly, Vidio, Bukalapak, and a major provider of online travel services.

4

What are the potential consequences of this OAuth flaw?

The OAuth flaw could result in unauthorized account access, compromising sensitive user information.

5

How does the article suggest organizations mitigate this risk?

The article implies that organizations need to ensure proper configuration and security assessments of their OAuth authentication systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203