CVE-2026-94151: Omega Solution HRM OS Role Permission API permission missing authentication
A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are within the disclosed affected range?
Omega Solution HRM OS versions up to 20260717 are identified as affected. The issue involves the Role Permission API endpoint at /role-permission/permission.
Does an attacker need credentials or user interaction?
No. The supplied vector indicates no privileges and no user interaction are required, and the attack can be launched remotely.
What input is involved in exploitation?
The disclosed manipulation targets the roleId argument. Successful manipulation can result in missing authentication for an unknown function associated with the affected endpoint.
Is exploit code available?
Yes. The disclosure states that an exploit has been made public and could be used in attacks.
Has the vendor provided a response or remediation?
The vendor was contacted early about the disclosure but did not respond. No vendor remediation or workaround is provided in the available data.