PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6376 SpiceJet CVE debrief

CVE-2026-6376 describes an unauthenticated information-disclosure issue in SpiceJet’s public booking retrieval flow. Per CISA’s advisory, a user who knows or can guess a PNR and last name may retrieve full passenger booking details without authentication or additional verification, exposing sensitive personal, travel, and booking metadata. The issue is scored CVSS 3.1 7.5 (HIGH) and is accompanied in the source by SSVCv2 E:N/A:Y.

Vendor
SpiceJet
Product
Online Booking System
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-23
Original CVE updated
2026-04-23
Advisory published
2026-04-23
Advisory updated
2026-04-23

Who should care

SpiceJet web and application security teams, booking-platform owners, privacy and compliance teams, and incident responders responsible for customer-data exposure and public-facing retrieval portals.

Technical summary

The advisory describes a network-reachable booking lookup function that lacks proper access control. Using only a PNR and last name, an unauthenticated requester can access full passenger booking details and associated metadata. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating high confidentiality impact with no integrity or availability impact. The source also includes an SSVC note of E:N/A:Y dated 2026-04-22T06:00:00Z.

Defensive priority

High. This is a public-facing, unauthenticated data exposure affecting sensitive customer information, so it should be treated as an urgent access-control and privacy-risk issue.

Recommended defensive actions

  • Disable or tightly gate the public booking-retrieval function until server-side authentication and authorization are enforced.
  • Replace PNR-plus-last-name lookup with stronger verification and minimize the data returned to only what is operationally necessary.
  • Add monitoring and logging for booking-lookup activity, including repeated or high-volume queries that may indicate enumeration.
  • Review whether customer booking data was exposed and follow internal privacy, legal, and incident-response procedures as appropriate.
  • Coordinate with SpiceJet using the published contact path and track remediation status before re-enabling any public retrieval capability.

Evidence notes

Based on CISA CSAF advisory ICSA-26-113-04 and its source JSON, both published on 2026-04-23, which state that SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed with only a PNR and last name and no authentication or verification. The source metadata also notes that SpiceJet did not respond to CISA’s coordination requests. No exploitation report or KEV listing is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6376 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6376

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6376 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6376

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.