CVE-2026-107702
Deferred Deferred - Pending Action

Authorization Bypass in QloApps via id_hotel Parameter

Vulnerability report for CVE-2026-107702, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. Attackers can modify the id_hotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Webkul QloApps 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in QloApps version 1.7.0 or earlier. It allows restricted back-office employees to access other hotels' data by manipulating the id_hotel URL parameter. Attackers can view room availability and booking status of hotels outside their assigned profile access by simply changing this parameter.

Detection Guidance

Check QloApps admin panel logs for unusual access patterns or requests with modified id_hotel parameters. Monitor network traffic for repeated attempts to access /AdminHotelRoomsBookingController.php with varying id_hotel values. Inspect server logs for unauthorized data access attempts in room booking modules.

Impact Analysis

This vulnerability allows unauthorized access to sensitive hotel data including room availability and booking status. Lower-privilege employees could view, create, or modify bookings across hotels they shouldn't access, potentially causing booking conflicts, financial discrepancies, or data leaks.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR and HIPAA by enabling unauthorized access to sensitive personal and booking data. It compromises data confidentiality and integrity, potentially leading to compliance violations and legal consequences for affected organizations.

Mitigation Strategies

Apply the patch from pull request #1916 immediately. Restrict admin panel access to only necessary users. Implement server-side validation to ensure users can only access hotels they are authorized to manage. Update to the latest QloApps version beyond 1.7.0.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107702. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart