CRITICAL 9.8 CVE-2026-108707 Published 11 Oct 2026

Wukong_HRM Authentication Bypass Lets Attackers Access HR Data

Worried this affects your website?

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect.

Unauthenticated attackers can call every HRM API endpoint by omitting the AUTH-TOKEN header. This grants HR administrator access to:

  • Read payslips, salary history and employee personal data
  • Download attachments
  • Modify or delete company-wide HR records

Reference: CVE-2026-108707 on NVD

← Back to Security News