PatchSiren cyber security CVE debrief
CVE-2026-107702 Webkul CVE debrief
CVE-2026-107702 debrief: QloApps 1.7.0 authorization bypass vulnerability allows restricted employees to access other hotels' data by manipulating the id_hotel parameter in AdminHotelRoomsBookingController::postProcess(). Hotel management system administrators and security teams should assess exposure and prioritize remediation based on the CVE Program record and NVD vulnerability detail page information. The vulnerability has a medium severity with a CVSS score of 5.3 and affects QloApps through version 1.7.0.
- Vendor
- Webkul
- Product
- QloApps
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Hotel management system administrators and security teams should assess exposure and prioritize remediation based on the CVE Program record and NVD vulnerability detail page information. The vulnerability affects QloApps through version 1.7.0 and allows restricted employees to access other hotels' data. Administrators and security teams should review and restrict access to hotel data for back-office employees, update QloApps to a version that addresses the
Why it matters
CVE-2026-107702 is a medium-severity authorization bypass vulnerability in QloApps 1.7.0 that allows restricted employees to access other hotels' data. Hotel management system administrators and security teams should assess exposure and prioritize remediation.
- Restrictive access controls may not prevent unauthorized data access
- Hotel management system logs may require review for suspicious activity
- QloApps instances may require immediate patching or mitigation
Technical summary
QloApps 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. The vulnerability has a medium severity with a CVSS score of 5.3. The affected product is QloApps through version 1.7.0. There are no known exploit details or reports of exploitation. The vendor has not provided a patch or workaround, but developers have proposed fixes in issue-tracking systems. Hotel management system administrators and security teams should assess exposure and prioritize remediation.
Defensive priority
Medium priority for hotel management system administrators and security teams
Recommended defensive actions
- Review and restrict access to hotel data for back-office employees
- Update QloApps to a version that addresses the authorization bypass vulnerability
- Monitor hotel management system logs for suspicious activity
- Perform a thorough review of QloApps instances for exposure
- Implement compensating controls for exposed systems
- Track exceptions and retest remediated assets
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Official CVE Program record and NVD vulnerability detail page provide information on the authorization bypass vulnerability in QloApps 1.7.0. The CVE record was published on 2026-10-08T18:08:52.874Z and has not been modified since then. The vulnerability allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. There are no known exploit details or reports of exploitation. The vendor has not provided a patch or workaround, but developers have proposed fixes in issue-tracking systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107702 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107702
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107702 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107702
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107702.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Qloapps/QloApps/pull/1916
Supplemental source - issue-tracking, patch
-
Source reference
Unverified legacy reference
URL: https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@leediay/idor-book-now-qloapps-via-url
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/Qloapps/QloApps
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/qloapps-through-1.7.0-authorization-bypass-via-id-hotel-in-admin-room-booking
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.