CVE-2026-108707: Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect
WukongHRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the Wukong_HRM API can exploit it. No valid account, privileges, or user interaction are required.
What does an attacker need to do to bypass authentication?
The bypass is triggered by omitting the AUTH-TOKEN header when calling HRM API endpoints. This permits access equivalent to an HR administrator.
What data and actions are exposed?
An attacker can read payslips, salary history, and employee personal data, download attachments, and modify or delete company-wide HR records. The referenced proof-of-concept material includes salary-slip reading, employee PII export, and attachment download scenarios.
Are deployments affected by default?
The provided information indicates that the vulnerable ParamAspect behavior affects Wukong_HRM through commit 186115e. It does not identify any configuration prerequisite or mitigation that would prevent the bypass.