CVE-2026-108708: Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUtil
WukongHRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated low-privileged employee account can exploit it. No user interaction is required.
What access can an attacker gain or change?
An attacker can read company-wide payslips, salary records, bank cards, and personal data. They can also edit bank cards and delete employees, departments, and contracts.
Is exploitation limited to a particular employee scope or department?
No. The affected authorization and data-scope behavior grants access across all employees, allowing company-wide impact rather than limiting actions to the caller's own records or department.
How can an organization determine whether it is affected?
The issue affects Wukong_HRM through commit 186115e. Review the deployed source or build lineage for the EmployeeAspect behavior that assigns callers the HR administrator role and EmployeeUtil data-scope checks that return all employees.