PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6375 SpiceJet CVE debrief

CVE-2026-6375 describes a missing-authorization flaw in SpiceJet’s online booking system. According to the CISA CSAF advisory published on 2026-04-23, an unauthenticated attacker can query passenger name records (PNRs) and obtain associated passenger names because the booking API does not enforce access controls on an endpoint intended for authenticated profile access. The advisory also notes that PNR identifiers are predictable, which increases the practical risk of systematic enumeration. The issue is scored CVSS 3.1 7.5 (HIGH) and maps to CWE-639 (Authorization Bypass Through User-Controlled Key).

Vendor
SpiceJet
Product
Online Booking System
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-23
Original CVE updated
2026-04-23
Advisory published
2026-04-23
Advisory updated
2026-04-23

Who should care

Security teams responsible for web applications, booking or reservation platforms, identity and access control, API security, and data privacy should prioritize this issue. Operations, incident response, and compliance teams should also care because the flaw exposes passenger data through an internet-facing service.

Technical summary

The source advisory says the booking API lacks authorization checks, allowing unauthenticated queries for PNRs. Because the identifiers follow a predictable pattern, an attacker could enumerate valid records rather than needing prior access. The impact described in the source is confidentiality loss: passenger names tied to PNRs may be disclosed. The provided CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, consistent with network-reachable, low-complexity, unauthenticated information disclosure.

Defensive priority

High. The issue is externally reachable, requires no authentication, and directly exposes personal data. Treat it as a priority exposure review for any affected booking or customer-profile API surface.

Recommended defensive actions

  • Restrict the affected endpoint to authenticated, authorized users only.
  • Verify authorization on every PNR lookup and ensure access is bound to the requesting account or trusted support workflow.
  • Remove or randomize any predictable identifier patterns where feasible, and do not rely on obscurity as a control.
  • Add rate limiting, anomaly detection, and logging for repeated PNR lookup attempts and enumeration patterns.
  • Review exposed booking and profile APIs for similar missing-authentication or missing-authorization flaws.
  • Coordinate with SpiceJet using the contact information provided in the advisory if you operate or integrate with the affected system.

Evidence notes

All claims in this debrief are taken from the supplied CISA CSAF source item for ICSA-26-113-04 / CVE-2026-6375 and its listed references. The source states the flaw affects SpiceJet’s online booking system, that unauthenticated PNR queries are possible, that identifiers are predictable, and that SpiceJet did not respond to CISA’s coordination requests. The source also provides the CVSS vector and CWE-639 reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6375 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6375

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6375 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6375

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.