Description
SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via IDOR
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an insecure direct object reference that allows an authenticated attacker to send a PUT request to the employee update endpoint with any employee identifier and change the controlled fields, enabling account takeover, enumeration of employee records, and retrieval of confidential personal data. The direct exposure of an employee identifier without ownership validation creates a critical privilege escalation bug.

Affected Systems

SIMAC MyPHR version 1.1 is affected. No additional product versions are listed. Administrators should verify that any deployments of the 1.1 build are reviewed for this issue.

Risk and Exploitability

The CVSS score of 8.7 indicates a high impact severity. The EPSS score of less than 1% suggests that, as of current data, the exploitation probability is low. It is not listed in CISA KEV. Attackers need an authenticated session to reach the endpoint; once authenticated, the missing server‑side ownership check enables the takeover. Therefore, while the exploitation likelihood is modest, the potential impact is substantial if the vulnerability is exploited.

Generated by OpenCVE AI on September 18, 2026 at 01:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or upgrade to a fixed version of MyPHR.
  • Require multi‑factor authentication for all users to reduce the risk of credential compromise.
  • Restrict access to the /api/employes/put endpoint to privileged roles or trusted IP ranges until a patch is available.

Generated by OpenCVE AI on September 18, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Simac
Simac myphr
Vendors & Products Simac
Simac myphr

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.
Title SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id}
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T16:17:12.538Z

Reserved: 2026-05-18T19:22:26.747Z

Link: CVE-2026-47094

cve-icon Vulnrichment

Updated: 2026-09-17T16:17:05.743Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:09.323

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-47094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key