{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vhr--03abbd3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vhr_project:vhr:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85182"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vhr (\u003c= 03abbd3)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","privilege-escalation","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe vhr application, through commit 03abbd3, contains a critical authentication vulnerability that allows an authenticated user to reset the password of any account within the system. The flaw exists within the PUT /hr/pass endpoint, which fails to enforce a proper authorization check to verify that the account ID specified in the request body matches the identity of the authenticated user performing the request.\u003c/p\u003e\n\u003cp\u003eBy supplying an arbitrary account ID along with that account's current password in the request body, an attacker can successfully overwrite the credentials for that target account. This vulnerability is highly impactful as it enables privilege escalation or total account takeover, provided the attacker has valid authentication to the platform. This issue was identified as CVE-2026-85182 and represents a failure in backend access control logic that requires immediate attention for systems running vhr versions at or below commit 03abbd3.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to gain unauthorized access to any user account on the platform, including administrative accounts. This leads to complete loss of account integrity and potential exfiltration of sensitive personnel or HR data managed by the application. Because the vulnerability allows an attacker to control the authentication credentials of any target account, the impact is severe, potentially compromising the entire instance of the vhr application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch the vhr application immediately by updating to a commit version later than 03abbd3 that includes the authorization fix for the PUT /hr/pass endpoint.\u003c/li\u003e\n\u003cli\u003eImplement request validation logging for the PUT /hr/pass endpoint to identify requests where the authenticated user ID differs from the account ID provided in the payload.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for multiple password change requests originating from a single authenticated session that target different account IDs.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T17:22:10Z","date_published":"2026-09-03T17:22:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vhr-auth-bypass/","summary":"An authentication flaw in the vhr application through commit 03abbd3 allows authenticated attackers to perform unauthorized password changes for arbitrary accounts by manipulating the account ID in PUT requests.","title":"Authentication Bypass in vhr PUT /hr/pass Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-vhr-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Vhr (\u003c= 03abbd3)","version":"https://jsonfeed.org/version/1.1"}