A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90522 affects the password recovery functionality in jaychouchannel's Tourism-Management-System, specifically within the resetPass function of UsersController.java. With a CVSS score of 7.3, this vulnerability enables attackers to bypass or weaken password recovery mechanisms remotely, potentially allowing unauthorized account takeover. Organizations deploying this tourism management platform—including travel agencies, hotel chains, and booking platforms—face direct risk of credential compromise. The publicly disclosed exploit status elevates urgency, as threat actors can immediately leverage this weakness to gain unauthorized access to sensitive customer and business data.
While MITRE ATT&CK mapping is not yet assigned to this CVE, the underlying weakness (CWE-640: Weak Password Recovery Mechanism) aligns with credential access tactics. Casky's 754 mapped security skills, powered by Claude AI's extended reasoning capabilities, would detect attack patterns associated with account compromise by analyzing authentication anomalies, unusual password reset requests, and account access from suspicious locations. Practitioners using Casky would observe findings related to: abnormal login patterns following failed authentication attempts, multiple concurrent password reset requests, and access to the password recovery endpoint from unexpected network origins. These behavioral indicators, correlated across your security telemetry, reveal exploitation attempts targeting this weakness before successful account takeover occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90522. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation