Executive brief
A security flaw in SpiceJet's flight booking system allows unauthorized individuals to access passenger travel records. By exploiting a weakness in how the system identifies bookings, an attacker could systematically collect passenger names and travel details. This could lead to significant privacy breaches and the exposure of sensitive customer travel information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the SpiceJet booking API due to missing authorization checks on an endpoint intended for authenticated profile access (CWE-639). The API allows unauthenticated, remote attackers to query Passenger Name Records (PNRs) without providing credentials. Because PNR identifiers follow a predictable pattern, attackers can use automated scripts to systematically enumerate valid records and retrieve associated passenger names. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available.
Affected products
- SpiceJet Online Booking System All versions
CVE identifiers
- CVE-2026-6376
- CVE-2026-6375
Timeline
- 2026-04-23: disclosed
- 2026-04-23: advisory: CISA ICSA-26-113-04 published