PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107702 Webkul CVE debrief

CVE-2026-107702 debrief: QloApps 1.7.0 authorization bypass vulnerability allows restricted employees to access other hotels' data by manipulating the id_hotel parameter in AdminHotelRoomsBookingController::postProcess(). Hotel management system administrators and security teams should assess exposure and prioritize remediation based on the CVE Program record and NVD vulnerability detail page information. The vulnerability has a medium severity with a CVSS score of 5.3 and affects QloApps through version 1.7.0.

Vendor
Webkul
Product
QloApps
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Hotel management system administrators and security teams should assess exposure and prioritize remediation based on the CVE Program record and NVD vulnerability detail page information. The vulnerability affects QloApps through version 1.7.0 and allows restricted employees to access other hotels' data. Administrators and security teams should review and restrict access to hotel data for back-office employees, update QloApps to a version that addresses the

Why it matters

CVE-2026-107702 is a medium-severity authorization bypass vulnerability in QloApps 1.7.0 that allows restricted employees to access other hotels' data. Hotel management system administrators and security teams should assess exposure and prioritize remediation.

  • Restrictive access controls may not prevent unauthorized data access
  • Hotel management system logs may require review for suspicious activity
  • QloApps instances may require immediate patching or mitigation

Technical summary

QloApps 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. The vulnerability has a medium severity with a CVSS score of 5.3. The affected product is QloApps through version 1.7.0. There are no known exploit details or reports of exploitation. The vendor has not provided a patch or workaround, but developers have proposed fixes in issue-tracking systems. Hotel management system administrators and security teams should assess exposure and prioritize remediation.

Defensive priority

Medium priority for hotel management system administrators and security teams

Recommended defensive actions

  • Review and restrict access to hotel data for back-office employees
  • Update QloApps to a version that addresses the authorization bypass vulnerability
  • Monitor hotel management system logs for suspicious activity
  • Perform a thorough review of QloApps instances for exposure
  • Implement compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Official CVE Program record and NVD vulnerability detail page provide information on the authorization bypass vulnerability in QloApps 1.7.0. The CVE record was published on 2026-10-08T18:08:52.874Z and has not been modified since then. The vulnerability allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. There are no known exploit details or reports of exploitation. The vendor has not provided a patch or workaround, but developers have proposed fixes in issue-tracking systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107702 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107702

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107702 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107702

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107702.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Qloapps/QloApps/pull/1916

    Supplemental source - issue-tracking, patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@leediay/idor-book-now-qloapps-via-url

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Qloapps/QloApps

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/qloapps-through-1.7.0-authorization-bypass-via-id-hotel-in-admin-room-booking

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.