CVE-2026-93556
📛 CVE Title
Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini
Description
The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- INCIBE
- CVSS severity
- CRITICAL
- CVSS score
- 9.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N- Effective score
- 9.3 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-639 - Reserved
- 2026-09-18
- Published
- 2026-09-22 08:57 UTC
- Last updated
- 2026-09-22 10:15 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93556.json
- Linked Threat
- CVE-2026-93556 — Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 09:17:05 UTC
- NVD last modified
- 2026-09-22 19:41:38 UTC
- EPSS score
- 0.0031 (probability of exploitation in next 30 days)
- EPSS percentile
- 23.44% vs all CVEs — higher = more likely to be exploited, as of 2026-09-22
NVD / KEV / EPSS data refreshed 2026-09-23 02:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84341 - Assigner
- INCIBE
- Published
- Sep 22, 2026, 8:57:30 AM
- Updated
- Sep 22, 2026, 10:15:28 AM
- EUVD base score (CVSS 4.0)
-
9.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.3100
- Vendors
- Kompini
- Products
-
Tankuam Places (0 <25 November 2025)
- Aliases
-
GHSA-m39c-xj94-687f
ENISA description: The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Kompini | Tankuam Places |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:arcticwolf.com
Validate Group Policy and registry settings for Defender to ensure real-time protection, automatic remediation , and exclusion policies are secured. Temporary Workarounds Block Vulnerable Apps: Use Microsoft Defender Vulnerability Management to block or warn against execution of affected binaries for systems pending a patch .
2026-09-23 15:13 UTC -
web:feedly.com
Mitigation Immediately validate that JWT recovery tokens are bound to and verified against the specific userId parameter before processing password reset requests. Implement strict token-to-user mapping validation. Consider implementing additional verification steps such as email confirmation or security questions before allowing password resets.
2026-09-23 15:13 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-23 15:13 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-09-23 15:13 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:13 UTC -
web:vulmon.com
Unauthenticated Account Takeover via Password Reset Flaw. An unauthenticated attacker may reset the password for any account, including administrative accounts…
2026-09-23 15:13 UTC -
web:windowsforum.com
ShieldBreak, a newly published proof of concept from the researcher known as Nightmare Eclipse, claims to bypass Microsoft's July fix for the Microsoft Defender privilege-escalation flaw CVE - 2026 -50656, better known as RoguePlanet.
2026-09-23 15:13 UTC -
web:www.aikido.dev
None of these is a clean fix , which is why the decision on how to remediate depends on knowing what package versions are running in production and why. This post will cover how AI has accelerated CVE detection and discovery, the upgrade trap, what CVE remediation actually involves in 2026 , and how to solve the CVE remediation problem.
2026-09-23 15:13 UTC -
web:www.techtimes.com
July 2026 Patch Tuesday permanently removes the Kerberos RC4 rollback registry key on July 14, leaving service accounts with RC4-only material unable to authenticate. Administrators must also ...
2026-09-23 15:13 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-09-23 15:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-93556.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93556",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T10:11:47.216044Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T10:15:28.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tankuam Places",
"vendor": "Kompini",
"versions": [
{
"lessThan": "25 November 2025",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Xavi M\u00e1rquez Gonz\u00e1lez"
}
],
"datePublic": "2026-09-22T08:51:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2018usuariId\u2019 parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account."
}
],
"value": "The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2018usuariId\u2019 parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization bypass through User-Controlled key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T08:57:30.854Z",
"orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
"shortName": "INCIBE"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/direct-references-unsafe-objects-idor-tankuam-places-kompini"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The vulnerability was fixed by the Kompini team on 25 November 2025."
}
],
"value": "The vulnerability was fixed by the Kompini team on 25 November 2025."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
"assignerShortName": "INCIBE",
"cveId": "CVE-2026-93556",
"datePublished": "2026-09-22T08:57:30.854Z",
"dateReserved": "2026-09-18T09:33:15.572Z",
"dateUpdated": "2026-09-22T10:15:28.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}