CVE-2026-108707
Received Received - Intake

Authentication Bypass in Wukong HRM via ParamAspect

Vulnerability report for CVE-2026-108707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
WuKongOpenSource Wukong_HRM 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Wukong_HRM through commit 186115e. It exists in the ParamAspect component which is supposed to enforce authentication by checking for a valid AUTH-TOKEN header. However, when this header is omitted, the system fails to block access, allowing unauthenticated attackers to call any HRM API endpoint. This grants attackers HR administrator privileges without proper authorization.

Detection Guidance

To detect this vulnerability, check if unauthenticated requests to Wukong_HRM API endpoints return sensitive data. Use tools like curl to send requests without the AUTH-TOKEN header to endpoints like /hrmSalarySlipRecord/querySlipDetail/{id}, /adminFile/download/{fileId}, or /hrmEmployee/export. If responses include sensitive data, the system is likely vulnerable.

Impact Analysis

Attackers can gain unauthorized access to sensitive HR data including payslips, salary history, employee personal data, and attachments. They can also modify or delete company-wide HR records. The vulnerability allows complete HR administrator access, enabling full control over employee and company data without detection.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for data protection and access controls. It enables unauthorized access to personally identifiable information (PII) and protected health information (PHI), which are strictly regulated. Organizations using affected Wukong_HRM versions would fail compliance audits and face potential legal consequences.

Mitigation Strategies

Immediately update Wukong_HRM to a patched version beyond commit 186115e. Ensure ParamAspect enforces strict token validation for all API endpoints. Block unauthenticated requests to sensitive endpoints and audit access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart