Description
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The flaw is in the HrInfoController.updateHr method of lenve vhr 1.0‑SNAPSHOT. By tampering with the Password argument in a request to the updateHr endpoint, an attacker can bypass existing privilege checks because the application does not verify that the caller is authorized to effect the to elevate their privileges beyond the intended level, and the vulnerability is classified as CWE‑266 and CWE‑269.

Affected Systems

Only the 1.0‑SNAPSHOT release of lenve vhr is affected. No other versions or variants have been reported as impacted. The flaw resides in the HrMapper.xml configuration that maps the updateHr endpoint.

Risk and Exploitability

The CVSS score of 5.3 places the incident in the medium severity tier. Because the attack vector is remote, an adversary can remotely exploit the flaw by sending a crafted request to the updateHr endpoint. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not yet cataloged in CISA KEV. While there is no confirmed exploitation, the potential for privilege escalation combined with a remote access path means that the issue could provide attackers a foothold if other network or application exposure exists.

Generated by OpenCVE AI on September 15, 2026 at 17:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or update that corrects the privilege management flaw in lenve vhr. Restrict the HrInfoController.updateHr endpoint to users with appropriate authorization levels and validate the Password argument against the caller’s current privileges before applying HR update requests to detect anomalous activity, and perform regular audits to ensure that privilege changes are legitimate.
  • Perform a security audit of all HR‑related endpoints to verify that privilege checks are correctly enforced and detect any similar gaps.
  • Temporarily block external access to the HrInfoController.updateHr endpoint or enforce strict firewall rules to limit unauthorized traffic until a patch is deployed.

Generated by OpenCVE AI on September 15, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title lenve vhr HrMapper.xml HrInfoController.updateHr privileges management
First Time appeared Lenve
Lenve vhr
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*
Vendors & Products Lenve
Lenve vhr
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T13:57:56.833Z

Reserved: 2026-09-12T08:24:13.076Z

Link: CVE-2026-90501

cve-icon Vulnrichment

Updated: 2026-09-16T13:57:51.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T08:16:27.017

Modified: 2026-09-16T14:17:13.500

Link: CVE-2026-90501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management