CVE Database
/

CVE-2026-6375

Back to search

CVE-2026-6375

Published: Apr 23, 2026

Modified: Apr 24, 2026

PUBLISHED

Description

A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.

VendorProductVersions

SpiceJet

Online Booking System

affected
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now