CVE-2026-108707: Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect

Published Oct 11, 2026
·
Updated

WukongHRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

Affected Software

1 affected component
Wukong_HRM<=186115e

Event History

Oct 11, 2026
CVE Published
via MITRE·01:12 AM
Data Sourced
via MITRE·01:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker who can reach the Wukong_HRM API can exploit it. No valid account, privileges, or user interaction are required.

2

What does an attacker need to do to bypass authentication?

The bypass is triggered by omitting the AUTH-TOKEN header when calling HRM API endpoints. This permits access equivalent to an HR administrator.

3

What data and actions are exposed?

An attacker can read payslips, salary history, and employee personal data, download attachments, and modify or delete company-wide HR records. The referenced proof-of-concept material includes salary-slip reading, employee PII export, and attachment download scenarios.

4

Are deployments affected by default?

The provided information indicates that the vulnerable ParamAspect behavior affects Wukong_HRM through commit 186115e. It does not identify any configuration prerequisite or mitigation that would prevent the bypass.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203