Skip to main content
HIGH

CVE-2026-90524

jaychouchannel Tourism-Management-System Update Endpoint missing authentication

CVSS v3

7.3

HIGH

EPSS Score

0.7 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for aff

Technical details

Published
2026-09-13
Last Modified
2026-09-13

Frequently asked questions

What is CVE-2026-90524?

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for aff

Is CVE-2026-90524 actively exploited?

Active exploitation of CVE-2026-90524 has not been confirmed. Its EPSS score was 0.7% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-90524?

CVE-2026-90524 has a CVSS v3 base score of 7.3 (HIGH severity).

Is CVE-2026-90524 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key