---
cve: "CVE-2026-86284"
severity: "MEDIUM"
cvss: 5.3
epss: "5%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-07 08:17:14"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T17:56:09+02:00"
---

# CVE-2026-86284

> 5.3 MEDIUM

## Beschreibung

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://github.com/jaychouchannel/Tourism-Management-System/>
- <https://github.com/jaychouchannel/Tourism-Management-System/commit/d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86>
- <https://github.com/jaychouchannel/Tourism-Management-System/pull/14>
- <https://github.com/jaychouchannel/Tourism_Management_System/issues/8>
- <https://vuldb.com/cve/CVE-2026-86284>
- <https://vuldb.com/submit/905644>
- <https://vuldb.com/vuln/399444>
- <https://vuldb.com/vuln/399444/cti>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86284) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
