Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini
Tankuam Places, versions published before 25 November 2025.
INCIBE has coordinated the publication of a critical-severity vulnerability affecting Tankuam Places by Kompini, a software programme for managing municipal facilities. The vulnerability was discovered by Xavi Márquez González.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-93556: CVSS v4.0: 9.3| CVSS /AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-639
The vulnerability was fixed by the Kompini team on 25 November 2025.
CVE-2026-93556: the ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-93556 | Crítica | No | Kompini |


