CVE-2026-105836 | Webkul QloApps up to 1.7.0 ajaxProcessBulkUpdateRooms id_rooms authorization

SecurityVulns

A vulnerability marked as problematic has been reported in Webkul QloApps up to 1.7.0. Affected by this vulnerability is the function AdminProductsController::ajaxProcessBulkUpdateRooms. This manipulation of the argument id_rooms causes authorization bypass.

This vulnerability is handled as CVE-2026-105836. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More