CVE-2026-94151: Omega Solution HRM OS Role Permission API permission missing authentication

Published Sep 21, 2026
·
Updated

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

2 affected components
Omega Solution HRM OS<=20260717
Omega Solution Role Permission API

Event History

Sep 21, 2026
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are within the disclosed affected range?

Omega Solution HRM OS versions up to 20260717 are identified as affected. The issue involves the Role Permission API endpoint at /role-permission/permission.

2

Does an attacker need credentials or user interaction?

No. The supplied vector indicates no privileges and no user interaction are required, and the attack can be launched remotely.

3

What input is involved in exploitation?

The disclosed manipulation targets the roleId argument. Successful manipulation can result in missing authentication for an unknown function associated with the affected endpoint.

4

Is exploit code available?

Yes. The disclosure states that an exploit has been made public and could be used in attacks.

5

Has the vendor provided a response or remediation?

The vendor was contacted early about the disclosure but did not respond. No vendor remediation or workaround is provided in the available data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203