Description
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to employee HR records
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in IceHRM before v36.0.0 arises from missing ownership validation on seven REST sub‑resource endpoints, allowing any authenticated employee to retrieve the HR records of other personnel. The flaw effectively bypasses normal access controls, exposing sensitive personal data such as skills, education, certifications, languages, leave, attendance and status. This is a classic information disclosure weakness (CWE‑639). No mechanism for executing code or causing denial of service is described, so based on the description it is inferred that the impact is limited to confidentiality.

Affected Systems

The affected product is IceHRM, maintained by gamonoid. All releases prior to 36.0.0 are vulnerable. The bug manifests on the core employee REST sub‑resource endpoints for skill, education, certification, language, leave, attendance and status. The product is identified by the CPE icehrm:icehrm and may be deployed in internal HR environments.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score is <1%, indicating a very low probability of exploitation. The lack of a KEV listing does not mitigate the risk. Attack vector requires authentication within the system; external code execution or denial of service cannot be performed through this flaw. If an authenticated user has access to the system, the flaw permits them to read any employee’s confidential records, potentially leading to privacy violations or insider‑threat exploitation.

Generated by OpenCVE AI on September 17, 2026 at 18:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade IceHRM to version 36.0.0 or later, which implements proper ownership validation on the affected REST endpoints.
  • If an upgrade is not feasible, apply the commit that fixes the validation logic (e.g., commit 19674f29a0591c985712dc4a5c841e21d7dbf971) or otherwise patch the code to enforce employee ownership checks.
  • In the interim, restrict or disable the vulnerable REST endpoints (skill, education, certification, language, leave, attendance, status) so that only privileged users can access them, or configure network‑level restrictions to block access until the patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gamonoid
Gamonoid icehrm
Vendors & Products Gamonoid
Gamonoid icehrm

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.
Title IceHRM before 36.0.0 Broken Access Control via Employee ID
First Time appeared Icehrm
Icehrm icehrm
Weaknesses CWE-639
CPEs cpe:2.3:a:icehrm:icehrm:*:*:*:*:*:*:*:*
Vendors & Products Icehrm
Icehrm icehrm
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:23.100Z

Reserved: 2026-09-15T00:45:12.081Z

Link: CVE-2026-91770

cve-icon Vulnrichment

Updated: 2026-09-15T14:46:56.378Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T02:16:49.517

Modified: 2026-09-23T17:17:47.840

Link: CVE-2026-91770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key