CRITICAL
9.8 CVE-2026-108707 Published 11 Oct 2026
Wukong_HRM Authentication Bypass Lets Attackers Access HR Data
Worried this affects your website?
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect.
Unauthenticated attackers can call every HRM API endpoint by omitting the AUTH-TOKEN header. This grants HR administrator access to:
- Read payslips, salary history and employee personal data
- Download attachments
- Modify or delete company-wide HR records
Reference: CVE-2026-108707 on NVD
← Back to Security News