CVE-2026-90523 | jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09 User Register Endpoint UsersController.java UsersEntity privileges management

SecurityVulns

A vulnerability labeled as critical has been found in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-90523. The attack can be launched remotely. Moreover, an exploit is present.

This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More