Security Advisory

CVE-2026-6375

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-23 20:07:23
Last updated 2026-04-24 18:19:59
Assigner icscert
CVSS score 8.7
State PUBLISHED

Description

A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.