Junglewise Threat Intelligence

CVE-2026-90522: jaychouchannel Tourism-Management-System weak password recovery

CVE-2026-90522 · Severity: high · CVSS 7.3 · Published 2026-09-13

Technologies: Jaychouchannel Tourism Management System. Vendors: Jaychouchannel.

Executive brief

A tourism management platform built on Spring Boot and Vue.js contains a weakness in its password reset functionality that allows unauthorized password changes. An attacker can remotely reset user passwords without proper verification, potentially gaining unauthorized access to customer and operational accounts.

Technical details

The vulnerability exists in the resetPass function of UsersController.java within the Password Recovery component, where insufficient authentication controls allow weak or unauthorized password recovery. The flaw is accessible remotely and does not require prior authentication, though the exact attack preconditions are not fully detailed in available sources. An attacker can exploit this to reset arbitrary user passwords without valid credentials or verification. The vulnerability has been patched in commit 9cb6215ac871f99a90cde763cf003e95ff282283, which implements old password verification requirements for password reset operations.

Affected products

  • jaychouchannel Tourism-Management-System up to commit d984d172dceca907f8b447efbdb06dc233f7938d

Timeline

  • 2026-09-13: disclosed
  • 2026-09-13: patched: Patch commit 9cb6215ac871f99a90cde763cf003e95ff282283 includes old password verification requirement

References

Related threats