{"id":"CVE-2026-107702","title":"QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter","summary":"QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. Attacke…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T19:17:02.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107702","references":[{"url":"https://github.com/Qloapps/QloApps","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php#L138-L139","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Qloapps/QloApps/pull/1916","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/@leediay/idor-book-now-qloapps-via-url","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/qloapps-through-1.7.0-authorization-bypass-via-id-hotel-in-admin-room-booking","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/@leediay/idor-book-now-qloapps-via-url","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"ingestedAt":"2026-10-08T18:58:11.314Z","slug":"CVE-2026-107702","body":"## Overview\n\nQloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. Attackers can modify the id_hotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}