Executive brief
A security flaw in SpiceJet's online booking portal allows unauthorized individuals to access private passenger information. By entering only a booking reference (PNR) and a last name, an attacker can view full travel itineraries and personal metadata without any further identity verification. This could lead to the exposure of sensitive customer data and travel plans for any passenger whose booking details can be guessed or obtained.
Technical details
The vulnerability is classified as a missing authentication for a critical function (CWE-306) within SpiceJet's public-facing booking retrieval component. The system fails to implement sufficient access controls or multi-factor verification, relying solely on the Passenger Name Record (PNR) and the passenger's last name to grant access to sensitive records. An attacker can exploit this over the network by supplying these two values to the retrieval endpoint. Because PNRs often follow predictable patterns or may be leaked via physical boarding passes, this allows for the unauthorized disclosure of full booking metadata and personal identifiable information (PII). As of the advisory date, the vendor has not responded to coordination efforts, and no official patch has been confirmed.
Affected products
- SpiceJet Online Booking System All versions
Timeline
- 2026-04-23: disclosed: Initial publication of ICS-CERT advisory ICSA-26-113-04
- 2026-04-23: advisory: CVE-2026-6376 published to NVD