CVE-2026-86282
Last modified
CVE-2026-86282 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. A patch should be applied to remediate this issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jaychouchannel | Tourism-Management-System | 8122bf020d91199eddfff3ee02d1632a70a9a132 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86282?
How severe is CVE-2026-86282?
How do I fix CVE-2026-86282?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86277A vulnerability has been found in SourceCodester Syllabus-Al…7.3
- CVE-2026-86278A vulnerability was found in SourceCodester Syllabus-Aligned…4.3
- CVE-2026-86279A vulnerability was determined in SourceCodester Syllabus-Al…6.3
- CVE-2026-8628The EntreDroppers plugin for WordPress is vulnerable to Refl…6.1
- CVE-2026-86280A vulnerability was identified in SourceCodester Syllabus-Al…5.3
- CVE-2026-86281A security flaw has been discovered in SourceCodester Syllab…4.3
- CVE-2026-86283MISP's UiBeta theme collection view (app/View/Themed/UiBeta/…7.1
- CVE-2026-86284A security vulnerability has been detected in jaychouchannel…5.3
- CVE-2026-86285A vulnerability was detected in BookStack up to 26.05.2. Aff…4.3
- CVE-2026-86287Net::IP::LPM versions before 1.12 for Perl accept malformed …7.5
- CVE-2026-86288A vulnerability has been found in ModelCloud GPTQModel up to…6.3
- CVE-2026-86289A vulnerability was found in Ollama up to 0.31.1. This issue…4.3
Are you affected by CVE-2026-86282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
