๐Ÿ” CVE Alert

CVE-2026-105836

MEDIUM 5.4

QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive dates, disrupting availability and bookings.

CWE CWE-639
Vendor webkul
Product qloapps
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for webkul qloapps

Be the first to know when new medium vulnerabilities affecting webkul qloapps are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

Webkul / QloApps
0 โ‰ค 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Qloapps/QloApps/pull/1892 github.com: https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminProductsController.php#L5344 hackmd.io: https://hackmd.io/@leediay/H189W20qfg github.com: https://github.com/Qloapps/QloApps vulncheck.com: https://www.vulncheck.com/advisories/qloapps-through-1.7.0-authorization-bypass-via-ajaxprocessbulkupdaterooms

Credits

leediay153 from Viettel Post