🔐 CVE Alert

CVE-2026-93556

UNKNOWN 0.0

Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.

CWE CWE-639
Vendor kompini
Product tankuam places
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for kompini tankuam places

Be the first to know when new unknown vulnerabilities affecting kompini tankuam places are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Kompini / Tankuam Places
0 < 25 November 2025

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/direct-references-unsafe-objects-idor-tankuam-places-kompini

Credits

Xavi Márquez González