Description
Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
Published: 2026-10-11
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Wukong_HRM around commit 186115e allows any authenticated user, even those with low privileges, to assume the role of a full HR administrator due to a flaw in EmployeeAspect. The flaw causes EmployeeUtil to return all employees in a data‑scope check, permitting abuse of sensitive endpoints. As a result, a malicious actor can read private payslips, salary histories, bank card numbers, social security identifiers, modify bank card information, and delete employees, departments, or contracts across the entire organization. The consequence is a loss of confidentiality, integrity, and potential availability of crucial HR data.

Affected Systems

WuKongOpenSource’s Wukong_HRM application is affected. The break in authorizationability exists in the codebase at commit 186115e, which has been identified as the point where EmployeeAspect assigns the HR administrator role to all callers and EmployeeUtil data scopes become unconstrained. No specific version range is listed, but any build that includes or has not yet applied the changes from the commit is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity due to the broad scope and significant impact on proprietary HR data. Although EPSS is not available and the vulnerability is not listed in KEV, the exposure to an authenticated user lowers the required attack conditions compared to an unauthenticated exploit. An attacker must be authenticated to the web application, but any logged‑in employee can trigger the unauthorized actions, making exploitation straightforward once credentials are obtained. The vulnerability is likely to be present in versions that contain commit 186115e or any earlier releases that have not incorporated a patch that restores proper authorization checks.

Generated by OpenCVE AI on October 11, 2026 at 03:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Wukong_HRM to a version that contains the corrected EmployeeAspect and EmployeeUtil authorization logic.
  • If an official update is not yet released, temporarily disable or remove the code in EmployeeAspect that automatically assigns the HR administrator role, and restrict data-scope checks in EmployeeUtil to the current user’s organization only.
  • Implement an explicit role‑ and permission‑based access control layer that validates each request against the user’s assigned roles before exposing sensitive HR endpoints or allowing modifications.

Generated by OpenCVE AI on October 11, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
Title Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUtil
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:12:32.478Z

Reserved: 2026-10-10T23:51:27.240Z

Link: CVE-2026-108708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:39.650

Modified: 2026-10-11T02:16:39.650

Link: CVE-2026-108708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T03:30:13Z

Weaknesses