{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/simac/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:simac:myphr:1.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-47094"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MyPHR (1.1)"],"_cs_severities":["high"],"_cs_tags":["idor","web-vulnerability","vulnerability","cve-2026-47094"],"_cs_type":"advisory","_cs_vendors":["SIMAC"],"content_html":"\u003cp\u003eSIMAC MyPHR version 1.1 contains an Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-47094. The vulnerability arises from missing server-side ownership validation, which allows an authenticated attacker to manipulate records belonging to other users. By crafting specific HTTP requests, an attacker can enumerate employee records, access sensitive personally identifiable information (PII) including private pay bulletins, and perform unauthorized account takeovers. Because the flaw lies in the backend access control logic, the impact is significant for organizations relying on this software to manage employee data. Defenders should prioritize updating instances of MyPHR and investigate application logs for unusual patterns of sequential ID access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized access to sensitive employee PII and the potential for account takeover. This exposure threatens the confidentiality and integrity of human resources data, potentially leading to identity theft or financial fraud involving pay records.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of SIMAC MyPHR to a patched version once released by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for high volumes of PUT requests targeting sequential or unauthorized employee identifiers.\u003c/li\u003e\n\u003cli\u003eImplement stricter access controls at the API gateway level to validate ownership of requested resource IDs before forwarding requests to the MyPHR backend.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T19:51:47Z","date_published":"2026-09-16T19:51:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-47094/","summary":"SIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.","title":"IDOR Vulnerability in SIMAC MyPHR","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-47094/"}],"language":"en","title":"CraftedSignal Threat Feed - SIMAC","version":"https://jsonfeed.org/version/1.1"}