<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:simac:myphr:1.1:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asimacmyphr1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 19:51:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asimacmyphr1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IDOR Vulnerability in SIMAC MyPHR</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-47094/</link><pubDate>Wed, 16 Sep 2026 19:51:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-47094/</guid><description>SIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.</description><content:encoded><![CDATA[<p>SIMAC MyPHR version 1.1 contains an Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-47094. The vulnerability arises from missing server-side ownership validation, which allows an authenticated attacker to manipulate records belonging to other users. By crafting specific HTTP requests, an attacker can enumerate employee records, access sensitive personally identifiable information (PII) including private pay bulletins, and perform unauthorized account takeovers. Because the flaw lies in the backend access control logic, the impact is significant for organizations relying on this software to manage employee data. Defenders should prioritize updating instances of MyPHR and investigate application logs for unusual patterns of sequential ID access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized access to sensitive employee PII and the potential for account takeover. This exposure threatens the confidentiality and integrity of human resources data, potentially leading to identity theft or financial fraud involving pay records.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of SIMAC MyPHR to a patched version once released by the vendor.</li>
<li>Monitor web application logs for high volumes of PUT requests targeting sequential or unauthorized employee identifiers.</li>
<li>Implement stricter access controls at the API gateway level to validate ownership of requested resource IDs before forwarding requests to the MyPHR backend.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>idor</category><category>web-vulnerability</category><category>vulnerability</category><category>cve-2026-47094</category></item></channel></rss>