CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-108707 — Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit...

·Source: NIST NVD

Updated:

Executive Summary

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

Analysis

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records. CVSS Score: 9.8. Published: 2026-10-11T02:16:39.477.

Indicators of Compromise (1)

CVE (1)
CVE-2026-108707
Source Attribution

Originally published by NIST NVD on Oct 11, 2026. Verified by: NIST.

Related Threats