CVE-2026-105836
Deferred Deferred - Pending Action

Authorization Bypass in QloApps via AdminProductsController

Vulnerability report for CVE-2026-105836, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive dates, disrupting availability and bookings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Webkul QloApps 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

QloApps version 1.7.0 has an authorization bypass flaw in the AdminProductsController::ajaxProcessBulkUpdateRooms function. Hotel-restricted back-office employees can exploit this to modify rooms belonging to other hotels by submitting foreign room IDs in the id_rooms parameter. This allows changing room status, floor, comments, or inactive dates without proper authorization.

Detection Guidance

Check QloApps admin panel access logs for unauthorized POST requests to AdminProductsController::ajaxProcessBulkUpdateRooms with foreign room IDs in the id_rooms parameter. Review database changes to room status, floor, comments, or inactive dates for unexpected modifications.

Impact Analysis

If you are a hotel-restricted back-office user, attackers could exploit this to alter your hotel's room details, causing booking disruptions, incorrect availability, or financial losses. Guests may face overbookings or unbookable rooms due to unauthorized modifications.

Compliance Impact

This vulnerability could lead to unauthorized data modifications, potentially violating integrity requirements in GDPR or HIPAA. Unauthorized changes to room data may result in non-compliance with data accuracy and access control provisions.

Mitigation Strategies

Update QloApps to the latest version beyond 1.7.0. Restrict admin panel access to authorized personnel only. Implement input validation to reject foreign room IDs in bulk update requests. Monitor database changes for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105836. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart