CVE-2026-85214: vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite

Published Sep 3, 2026
·
Updated

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.

Event History

Sep 3, 2026
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated to the application. The attacker does not need user interaction and can target other HR profiles, including administrator accounts.

2

What access is needed to overwrite another profile?

The affected endpoint accepts a profile ID supplied in the request body without validating that the authenticated user is authorized to modify that profile. An authenticated user who can send a PUT request to /hr/info can provide another user's profile ID.

3

What is the practical impact?

An attacker can overwrite other users' names and addresses and can disable accounts. Disabling administrator accounts can cause denial of service.

4

How can I tell whether an attempted exploitation occurred?

Review PUT /hr/info requests for profile IDs that do not belong to the authenticated requester, and investigate unexpected changes to HR profile fields or account disablement, particularly for administrator accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203