CVE-2026-86284 Details
Description
A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.
A vulnerability allowing information disclosure has been identified in the Jaychouchannel Tourism Management System, specifically in versions up to commit 8122bf020d91199eddfff3ee02d1632a70a9a132. The issue arises in the 'getOption' function of 'CommonController.java', where the 'option' API endpoint can be accessed without authentication. This endpoint allows users to specify database table and column names, which are then queried directly. As a result, sensitive information, such as password data from the 'users' table, can be exposed. The vulnerability can be exploited remotely.
Users are advised to update to the latest version of the Jaychouchannel Tourism Management System, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jaychouchannel/Tourism-Management-System/ | [email protected] | ProductSource CodeVendor |
| https://github.com/jaychouchannel/Tourism-Management-System/commit/d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86 | [email protected] | Source CodeVendor |
| https://github.com/jaychouchannel/Tourism_Management_System/issues/8 | [email protected] | |
| https://github.com/jaychouchannel/Tourism-Management-System/pull/14 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-86284 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/905644 | [email protected] | Permission Required |
| https://vuldb.com/vuln/399444 | [email protected] | Permission Required |
| https://vuldb.com/vuln/399444/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jaychouchannel Tourism-Management-System | 8122bf020d91199eddfff3ee02d1632a70a9a132 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion