CVE-2026-105836
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
06/10/2026
Last modified:
06/10/2026
Description
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive dates, disrupting availability and bookings.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
5.40
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/Qloapps/QloApps
- https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminProductsController.php#L5344
- https://github.com/Qloapps/QloApps/pull/1892
- https://hackmd.io/@leediay/H189W20qfg
- https://www.vulncheck.com/advisories/qloapps-through-1.7.0-authorization-bypass-via-ajaxprocessbulkupdaterooms


