TROYANOSYVIRUS
Voltar para CVEs

CVE-2026-6376

N/A

Descricao

A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess those basic inputs. The issue arises from improper access control on a sensitive data retrieval function.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado4/23/2026
Ultima modificacao4/24/2026
Fontenvd
Avistamentos honeypot0

Fraquezas (CWE)

CWE-306

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.