Un nuevo aviso de seguridad

Imported from official source

Advisory

Cybersecurity Classified by Officially

Un nuevo aviso de seguridad Referencia directa a objetos inseguros (IDOR) en Tankuam Places de Kompini Fecha22/09/2026 Importancia5 - Crítica Recursos Afectados Tankuam Places, versiones publicadas anteriores al 25/11/2025. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad crítica que afecta a Tankuam Places de Kompini, software para la gestión de los equipamientos municipales. La vulnerabilidad ha sido descubierta por Xavi Márquez González.A esta vulnerabilidad se le ha asignado el siguiente código, puntuación base CVSS v4.0, vector del CVSS y el tipo de vulnerabilidad CWE:CVE-2026-93556: CVSS v4.0: 9.3| CVSS AV:X /AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-639 Solución La vulnerabilidad ha sido solucionada por el equipo de Kompini el día 25/11/2025. Detalle CVE-2026-93556: el endpoint ‘/password/guardarClau/recover’ acepta el parámetro ‘usuariId’, que determina la cuenta cuya contraseña será modificada. El token JWT del proceso de recuperación no se valida frente al usuario indicado en ese parámetro. Un atacante no autenticado podría manipular el identificador y restablecer la contraseña de cualquier cuenta, incluidas cuentas ...

Read the original at the source: https://www.incibe.es/node/662582

Officially imported this from INCIBE’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
INCIBE — imported from official source
Official source
https://www.incibe.es/rss.xml RSS
Imported
September 24, 2026 11:30
Versions
1 recorded
Identity
662582 at https://www.incibe.es

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.