Skip to content
Threat Feed
critical advisory

Authentication Bypass in Wukong_HRM ParamAspect

Wukong_HRM up to commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to access sensitive HR administrative API endpoints.

CVE search metadata

CVE search record: CVE-2026-108707. Severity: critical. CVSS: 9.8. KEV: no. Product: Wukong_HRM (<= commit 186115e). Brief: Authentication Bypass in Wukong_HRM ParamAspect. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wukong-hrm-auth-bypass/

Wukong_HRM, a human resource management platform, contains a critical authentication bypass vulnerability in the ParamAspect component affecting all versions through commit 186115e. The vulnerability resides in the application's request processing logic, which improperly validates authentication tokens. Specifically, the system fails to enforce security checks if the required 'AUTH-TOKEN' header is simply omitted from the HTTP request. This flaw allows unauthenticated remote attackers to interact with restricted API endpoints that are intended for HR administrators only. Successful exploitation grants attackers unauthorized access to sensitive company-wide HR information, including employee personal data, salary histories, and payslips. Furthermore, attackers can leverage this access to modify or delete critical HR records, leading to potential data integrity loss and severe privacy breaches.

Impact

The vulnerability carries a CVSS v3.1 base score of 9.8, indicating its severity. If exploited, an attacker gains full HR administrator privileges. Potential damage includes the mass exfiltration of sensitive employee PII and payroll information, unauthorized termination of employees, modification of compensation records, and deletion of internal HR documentation. Any organization using Wukong_HRM versions up to commit 186115e is currently at risk of full administrative compromise.

Recommendation

  1. Immediately audit all web server logs for HTTP requests to the Wukong_HRM API that do not contain the 'AUTH-TOKEN' header, as these may indicate exploitation attempts.
  2. Patch Wukong_HRM by updating to a version beyond commit 186115e.
  3. Deploy web application firewall (WAF) rules to inspect incoming traffic and block API requests missing the mandatory 'AUTH-TOKEN' header.

Immediate actions

Patch Wukong_HRM to a version post-commit 186115e

IT Operations 24h

Threat Hunt

Search logs for 200 OK responses to /api/ endpoints that lack the AUTH-TOKEN header

T1190 high high confidence hunt now

Data: Web server access logs with full header visibility

Mitigations

Implement WAF rule to block requests to /api/ where AUTH-TOKEN header is missing

immediate IT Operations

CVE-2026-108707

Detection coverage 1

Detect CVE-2026-108707 Exploitation - Missing AUTH-TOKEN Header

critical

Detects potential CVE-2026-108707 exploitation by identifying HTTP requests to Wukong_HRM API endpoints that lack the required AUTH-TOKEN header.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →