Junglewise Threat Intelligence

CVE-2026-14725: SourceCodester Online Boat Reservation System insufficient session expiration

CVE-2026-14725 · Severity: medium · CVSS 6.3 · Published 2026-07-05

Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Boat Reservation System, a web application used for managing boat bookings. The system fails to properly expire or invalidate user sessions, which could allow an unauthorized person to maintain access to an account even after a user attempts to log out or after a period of inactivity. This could lead to unauthorized access to customer reservation data or personal information.

Technical details

A vulnerability classified as CWE-613 (Insufficient Session Expiration) exists in SourceCodester Online Boat Reservation System 1.0. The application fails to properly invalidate session identifiers upon logout or after a period of inactivity, leading to persistent sessions. An attacker with low-level privileges can exploit this remotely to maintain access to the system or hijack sessions that should have expired. The exploit is reportedly publicly available, and the vulnerability can be triggered over the network without user interaction, provided the attacker has initial authenticated access.

Affected products

  • SourceCodester Online Boat Reservation System 1.0

Timeline

  • 2026-07-05: disclosed: Initial publication of the vulnerability details.
  • 2026-07-05: advisory

References

Related threats