Unauthorized Password Reset Vulnerability in Tankuam Places by Kompini
CVE-2026-93556

9.3CRITICAL

Key Information:

Vendor

Kompini

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93556?

The password recovery function in Tankuam Places fails to adequately verify the user's identity when resetting passwords. Specifically, the '/password/guardarClau/recover' endpoint accepts the 'usuariId' parameter without validating its association with the provided JWT token. This oversight allows an attacker to exploit the endpoint by manipulating the identifier, potentially leading to unauthorized password resets. As a result, this vulnerability can grant unsolicited access to user accounts, including those of administrative profiles, compromising sensitive data and system integrity.

Affected Version(s)

Tankuam Places 0 < 25 November 2025

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xavi Márquez González
.