Unauthorized Password Reset Vulnerability in Tankuam Places by Kompini
CVE-2026-93556
9.3CRITICAL
What is CVE-2026-93556?
The password recovery function in Tankuam Places fails to adequately verify the user's identity when resetting passwords. Specifically, the '/password/guardarClau/recover' endpoint accepts the 'usuariId' parameter without validating its association with the provided JWT token. This oversight allows an attacker to exploit the endpoint by manipulating the identifier, potentially leading to unauthorized password resets. As a result, this vulnerability can grant unsolicited access to user accounts, including those of administrative profiles, compromising sensitive data and system integrity.
Affected Version(s)
Tankuam Places 0 < 25 November 2025
