CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-108707 — Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit...
·Source: NIST NVD
Updated:
Executive Summary
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.
Analysis
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records. CVSS Score: 9.8. Published: 2026-10-11T02:16:39.477.