CVE-2026-93556: Kompini Tankuam Places

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.

Affected products

  • Kompini Tankuam Places: before 25 November 2025 (fixed in 25 November 2025)

Published 2026-09-22. Last modified 2026-09-22.