{"id":"CVE-2026-90524","title":"A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09","summary":"A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation resul…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-287","CWE-306"],"vendor":"jaychouchannel","product":"Tourism-Management-System","affected":["Tourism-Management-System 229956e20dbd4a80eeff14535e44d3099502af09"],"published":"2026-09-13","updated":"2026-09-15","sourceUpdated":"2026-09-15T15:17:28.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90524","references":[{"url":"https://github.com/jaychouchannel/Tourism-Management-System/","label":"cna@vuldb.com"},{"url":"https://github.com/jaychouchannel/Tourism-Management-System/commit/84d8ec384f669df3985293dab293bb7b477efa64","label":"cna@vuldb.com"},{"url":"https://github.com/jaychouchannel/Tourism-Management-System/issues/11","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90524","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/912245","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403114","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403114/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00693,"epssPercentile":0.51051,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-15T13:47:33.248578Z"},"ingestedAt":"2026-09-14T15:23:07.470Z","slug":"CVE-2026-90524","body":"## Overview\n\nA security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":203727,"id":"CVE-2026-90524","ts":1789483138676,"field":"exploit_available","old":"false","new":"true"}]}