Impact
The vulnerability exists in the Role Permission Retrieval endpoint of Omega Solution HRM OS. By manipulating the roleId argument, an attacker can control resource identifiers and retrieve or modify permissions for arbitrary roles. This enables unauthorized access to role permission data and may compromise the integrity of the system’s access control model.
Affected Systems
Omega Solution HRM OS versions up to 20260717 are affected. The flaw resides in the /role-permission/permission endpoint of the Role Permission Retrieval component.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. The EPSS score is unavailable, and the vulnerability is not listed in KEV. The attack can be launched remotely and exploit code is publicly available, suggesting that attackers may try this vector. Because the flaw is a resource injection (CWE-99), the likelihood of exploitation is higher if an attacker can submit crafted roleId values to the endpoint.
OpenCVE Enrichment