CISA warned that all versions of the SpiceJet Online Booking System contain two high-severity information disclosure flaws that can expose passenger data to unauthenticated users. The issues, tracked as CVE-2026-6375 and CVE-2026-6376, affect public-facing booking functions and were reported by Owais Shaikh. According to the advisory, one flaw allows attackers to enumerate valid passenger name records (PNRs) because authorization checks are missing and identifiers are predictable, while the other lets anyone retrieve full booking details using only a PNR and last name.
The vulnerabilities were rated CVSS 7.5 by CISA and described in CVE records as CWE-639 and CWE-306 weaknesses with low-complexity, network-based exploitation requiring no privileges or user interaction. Successful exploitation could disclose passenger names as well as broader personal, travel, and booking metadata, creating significant confidentiality risk for the transportation sector worldwide. CISA said it had no evidence of public exploitation targeting these flaws at the time of publication.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Zero Day Initiative published advisories ZDI-26-298 and ZDI-26-297 for Siemens SINEC NMS, publicly disclosing CVE-2026-24032 and CVE-2026-25654. The advisories detailed an authentication bypass and a privilege escalation issue following coordinated disclosure with Siemens.
CVE-2026-6375 and CVE-2026-6376 were recorded publicly, documenting unauthenticated access to passenger name records and booking details in SpiceJet's online booking system. The entries reference CISA's advisory and classify the issues as high-severity access control weaknesses.
CISA published ICS advisory ICSA-26-113-04 describing CVE-2026-6375 and CVE-2026-6376 in the SpiceJet Online Booking System. The vulnerabilities expose passenger booking data through weak or missing access controls, and CISA said it had no reports of known public exploitation at publication time.
Siemens released remediation updates for the SINEC NMS authentication bypass and privilege escalation vulnerabilities before coordinated public disclosure. The fixes addressed CVE-2026-24032 and CVE-2026-25654.
Rocco Calvi of TecSecurity reported a Siemens SINEC NMS privilege escalation vulnerability to the vendor, later assigned CVE-2026-25654. The issue involves improper authentication in the web service on TCP port 443 and could let an authenticated attacker access resources beyond intended privileges.
Zero Day Initiative notified Siemens of an authentication bypass vulnerability in Siemens SINEC NMS, later assigned CVE-2026-24032. The flaw affects the httpd authentication handler and could allow remote attackers to bypass authentication without prior access or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcezerodayinitiative.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.