PT-2026-33456 · Arnobt78 · Hotel Booking Management System

·

CVE-2026-6492

·

Published

2026-04-17

·

Updated

2026-08-02

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions arnobt78 Hotel Booking Management System versions prior to d47ae0e27c700b64dc417f7f01b84a6b1b0b6bd3
Description An issue in the Health Check Endpoint component allows remote exploitation through the manipulation of an unknown function within the '/api/health/detailed' endpoint, leading to information disclosure.
Recommendations Deploy patch d47ae0e27c700b64dc417f7f01b84a6b1b0b6bd3. Restrict access to the '/api/health/detailed' endpoint to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6492

Affected Products

Hotel Booking Management System