Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108707

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Oct 11, 2026
Vendor unknown

Description

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

References