Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini

Posted date 22/09/2026
Identificador
INCIBE-2026-654
Importance
5 - Critical
Affected Resources

Tankuam Places, versions published before 25 November 2025.

Description

INCIBE has coordinated the publication of a critical-severity vulnerability affecting Tankuam Places by Kompini, a software programme for managing municipal facilities. The vulnerability was discovered by Xavi Márquez González.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-93556: CVSS v4.0: 9.3| CVSS /AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-639
Solution

The vulnerability was fixed by the Kompini team on 25 November 2025.

Detail

CVE-2026-93556: the ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-93556 Crítica No Kompini
References list