Authentication Bypass in Wukong_HRM ParamAspect
Wukong_HRM up to commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to access sensitive HR administrative API endpoints.
CVE search metadata
CVE search record: CVE-2026-108707. Severity: critical. CVSS: 9.8. KEV: no. Product: Wukong_HRM (<= commit 186115e). Brief: Authentication Bypass in Wukong_HRM ParamAspect. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wukong-hrm-auth-bypass/
Wukong_HRM, a human resource management platform, contains a critical authentication bypass vulnerability in the ParamAspect component affecting all versions through commit 186115e. The vulnerability resides in the application's request processing logic, which improperly validates authentication tokens. Specifically, the system fails to enforce security checks if the required 'AUTH-TOKEN' header is simply omitted from the HTTP request. This flaw allows unauthenticated remote attackers to interact with restricted API endpoints that are intended for HR administrators only. Successful exploitation grants attackers unauthorized access to sensitive company-wide HR information, including employee personal data, salary histories, and payslips. Furthermore, attackers can leverage this access to modify or delete critical HR records, leading to potential data integrity loss and severe privacy breaches.
Impact
The vulnerability carries a CVSS v3.1 base score of 9.8, indicating its severity. If exploited, an attacker gains full HR administrator privileges. Potential damage includes the mass exfiltration of sensitive employee PII and payroll information, unauthorized termination of employees, modification of compensation records, and deletion of internal HR documentation. Any organization using Wukong_HRM versions up to commit 186115e is currently at risk of full administrative compromise.
Recommendation
- Immediately audit all web server logs for HTTP requests to the Wukong_HRM API that do not contain the 'AUTH-TOKEN' header, as these may indicate exploitation attempts.
- Patch Wukong_HRM by updating to a version beyond commit 186115e.
- Deploy web application firewall (WAF) rules to inspect incoming traffic and block API requests missing the mandatory 'AUTH-TOKEN' header.
Immediate actions
Patch Wukong_HRM to a version post-commit 186115e
Threat Hunt
Search logs for 200 OK responses to /api/ endpoints that lack the AUTH-TOKEN header
Data: Web server access logs with full header visibility
Mitigations
Implement WAF rule to block requests to /api/ where AUTH-TOKEN header is missing
CVE-2026-108707
Detection coverage 1
Detect CVE-2026-108707 Exploitation - Missing AUTH-TOKEN Header
criticalDetects potential CVE-2026-108707 exploitation by identifying HTTP requests to Wukong_HRM API endpoints that lack the required AUTH-TOKEN header.
Detection queries are available on the platform. Get full rules →