CVE-2026-75498 affects Webkul QloApps, a hotel booking and management platform. The vulnerability stems from insufficient validation of request parameters before database queries are executed. A remote attacker with administrative privileges can exploit this by sending a crafted SQL query through the 'bo_query' parameter in the 'Address.php' file. This constitutes a SQL injection vulnerability that could allow unauthorized data access or manipulation. The attack requires authentication with administrative-level privileges, reducing but not eliminating the risk. A fix has been committed in the QloApps GitHub repository at commit 123c97c. The issue is tracked under CVE-2026-75498 and referenced in a CISA advisory. Organizations using QloApps should apply the patch immediately to mitigate exposure.