High severityNVD Advisory· Published Apr 23, 2026· Updated Apr 24, 2026
CVE-2026-6375
CVE-2026-6375
Description
A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- SpiceJet Online Booking SystemCISA Alerts