Executive brief
Tankuam Places is software for managing municipal facilities. An unauthenticated attacker can reset any user's password, including administrator accounts, by manipulating a parameter in the password recovery endpoint. This allows complete account takeover without credentials or user interaction.
Technical details
The /password/guardarClau/recover endpoint fails to validate the JWT recovery token against the specified usuariId parameter, creating an insecure direct object reference (IDOR) vulnerability. An unauthenticated attacker can supply arbitrary user identifiers to reset passwords for any account, including administrative accounts, achieving account takeover via an identity manipulation attack.
Affected products
- Kompini Tankuam Places before 25 November 2025
Timeline
- 2026-09-22: disclosed
- 2025-11-25: patched