Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide. | |
| Title | Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUtil | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:12:32.478Z
Reserved: 2026-10-10T23:51:27.240Z
Link: CVE-2026-108708
No data.
Status : Received
Published: 2026-10-11T02:16:39.650
Modified: 2026-10-11T02:16:39.650
Link: CVE-2026-108708
No data.
OpenCVE Enrichment
Updated: 2026-10-11T03:30:13Z
Weaknesses