PatchSiren cyber security CVE debrief
CVE-2026-6375 SpiceJet CVE debrief
CVE-2026-6375 describes a missing-authorization flaw in SpiceJet’s online booking system. According to the CISA CSAF advisory published on 2026-04-23, an unauthenticated attacker can query passenger name records (PNRs) and obtain associated passenger names because the booking API does not enforce access controls on an endpoint intended for authenticated profile access. The advisory also notes that PNR identifiers are predictable, which increases the practical risk of systematic enumeration. The issue is scored CVSS 3.1 7.5 (HIGH) and maps to CWE-639 (Authorization Bypass Through User-Controlled Key).
- Vendor
- SpiceJet
- Product
- Online Booking System
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-04-23
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-04-23
Who should care
Security teams responsible for web applications, booking or reservation platforms, identity and access control, API security, and data privacy should prioritize this issue. Operations, incident response, and compliance teams should also care because the flaw exposes passenger data through an internet-facing service.
Technical summary
The source advisory says the booking API lacks authorization checks, allowing unauthenticated queries for PNRs. Because the identifiers follow a predictable pattern, an attacker could enumerate valid records rather than needing prior access. The impact described in the source is confidentiality loss: passenger names tied to PNRs may be disclosed. The provided CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, consistent with network-reachable, low-complexity, unauthenticated information disclosure.
Defensive priority
High. The issue is externally reachable, requires no authentication, and directly exposes personal data. Treat it as a priority exposure review for any affected booking or customer-profile API surface.
Recommended defensive actions
- Restrict the affected endpoint to authenticated, authorized users only.
- Verify authorization on every PNR lookup and ensure access is bound to the requesting account or trusted support workflow.
- Remove or randomize any predictable identifier patterns where feasible, and do not rely on obscurity as a control.
- Add rate limiting, anomaly detection, and logging for repeated PNR lookup attempts and enumeration patterns.
- Review exposed booking and profile APIs for similar missing-authentication or missing-authorization flaws.
- Coordinate with SpiceJet using the contact information provided in the advisory if you operate or integrate with the affected system.
Evidence notes
All claims in this debrief are taken from the supplied CISA CSAF source item for ICSA-26-113-04 / CVE-2026-6375 and its listed references. The source states the flaw affects SpiceJet’s online booking system, that unauthenticated PNR queries are possible, that identifiers are predictable, and that SpiceJet did not respond to CISA’s coordination requests. The source also provides the CVSS vector and CWE-639 reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6375 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6375
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6375 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6375
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.