top of page
perceptive_background_267k.jpg

SpiceJet Online Booking System

Published:

23 april 2026 om 12:00:00

Alert date:

23 april 2026 om 17:04:31

Source:

cisa.gov

Click to open the original link from this advisory

Web Technologies, Critical Infrastructure, Identity & Access, Data Breach & Exfiltration

SpiceJet's online booking system contains two high-severity vulnerabilities that allow unauthorized access to passenger data. CVE-2026-6375 enables unauthenticated users to query passenger name records (PNRs) through predictable identifiers due to missing authorization checks. CVE-2026-6376 allows access to full passenger booking details using only PNR and last name without authentication. Both vulnerabilities affect all versions of the SpiceJet Online Booking System and could lead to sensitive information disclosure. SpiceJet has not responded to CISA's coordination attempts, leaving the vulnerabilities unpatched.

Technical details

Mitigation steps:

Affected products:

SpiceJet Online Booking System

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page