logo

Check-in terminals used by thousands of hotels leak guest info

ID: 61a600a8-b547-507c-b28c-6760ca3a50a3

STIX ID: report--61a600a8-b547-507c-b28c-6760ca3a50a3

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ariane Systems self check-in terminals used by thousands of hotels contain a kiosk-mode bypass: specific inputs (e.g., a single quote or six dashes) can hang the Ariane Allegro Scenario Player, allow terminating the process, expose the Windows desktop, and thereby reveal guest PII and enable provisioning of RFID room keys. The flaw affects terminals deployed across ~3,000 hotels (500,000+ rooms); the researcher reported it to the vendor but an authoritative fixed version and remediation details are unclear—operators are advised to isolate kiosks and contact the vendor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.