CVE-2026-93556
Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.
| CWE | CWE-639 |
| Vendor | kompini |
| Product | tankuam places |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for kompini tankuam places
Be the first to know when new unknown vulnerabilities affecting kompini tankuam places are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Kompini / Tankuam Places
0 < 25 November 2025
References
Credits
Xavi Márquez González