CVE-2026-108708
Received Received - Intake

Missing Authorization in Wukong_HRM Allows Privilege Escalation

Vulnerability report for CVE-2026-108708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
WuKongOpenSource Wukong_HRM 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Wukong_HRM allows any authenticated low-privileged employee to access and modify sensitive data across the entire system. The issue stems from improper authorization checks in EmployeeAspect and EmployeeUtil components, which incorrectly assign HR administrator privileges to all users and return all employee data without validation.

Detection Guidance

To detect this vulnerability, check if your Wukong_HRM instance allows unauthorized access to sensitive endpoints. Use tools like curl to test endpoints such as POST /hrmEmployee/SocialSecurity/querySalaryList or POST /hrmSalaryArchives/querySalaryArchivesList with low-privileged credentials. If responses include data not belonging to the authenticated user, the system is likely vulnerable.

Impact Analysis

An attacker could read payslips, salary records, bank cards, and personal data of any employee. They could also edit bank cards, delete employees, departments, and contracts company-wide. This could lead to financial fraud, data breaches, and operational disruption.

Compliance Impact

This vulnerability likely violates GDPR's data protection principles by exposing personal and sensitive employee data without authorization. It also breaches HIPAA's access controls for protected health information if salary or personal data includes such details. Non-compliance risks include legal penalties, fines, and reputational damage.

Mitigation Strategies

Immediately update Wukong_HRM to a version beyond commit 186115e. Review and restrict access to sensitive endpoints by validating employee IDs against session data. Implement proper role-based access controls in EmployeeAspect and EmployeeUtil to ensure data-scope checks enforce correct permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart