CVE-2026-90522 Details
Description
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
A vulnerability exists in the Jaychou Tourism Management System in the Password Recovery component, specifically within the UsersController.java file. This issue, present in versions up to commit d984d172dceca907f8b447efbdb06dc233f7938d, allows for weak password recovery. The resetPass function can be exploited remotely, as it does not require authentication and sets a predictable password of '123456' for any account. The vulnerability has been publicly disclosed and could be actively exploited.
A patch has been released and is available in the main branch of the Jaychou Tourism Management System GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jaychouchannel/Tourism-Management-System/ | [email protected] | Source CodeVendor |
| https://github.com/jaychouchannel/Tourism-Management-System/commit/9cb6215ac871f99a90cde763cf003e95ff282283 | [email protected] | Source CodeVendor |
| https://github.com/jaychouchannel/Tourism-Management-System/issues/13 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-90522 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/912236 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403112 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/403112/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jaychouchannel Tourism-Management-System | <= d984d172dceca907f8b447efbdb06dc233f7938d |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion