{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wukong_hrm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wukong_hrm:wukong_hrm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-108707"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wukong_HRM (\u003c= commit 186115e)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","web-application","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Wukong_HRM"],"content_html":"\u003cp\u003eWukong_HRM, a human resource management platform, contains a critical authentication bypass vulnerability in the ParamAspect component affecting all versions through commit 186115e. The vulnerability resides in the application's request processing logic, which improperly validates authentication tokens. Specifically, the system fails to enforce security checks if the required 'AUTH-TOKEN' header is simply omitted from the HTTP request. This flaw allows unauthenticated remote attackers to interact with restricted API endpoints that are intended for HR administrators only. Successful exploitation grants attackers unauthorized access to sensitive company-wide HR information, including employee personal data, salary histories, and payslips. Furthermore, attackers can leverage this access to modify or delete critical HR records, leading to potential data integrity loss and severe privacy breaches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.8, indicating its severity. If exploited, an attacker gains full HR administrator privileges. Potential damage includes the mass exfiltration of sensitive employee PII and payroll information, unauthorized termination of employees, modification of compensation records, and deletion of internal HR documentation. Any organization using Wukong_HRM versions up to commit 186115e is currently at risk of full administrative compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately audit all web server logs for HTTP requests to the Wukong_HRM API that do not contain the 'AUTH-TOKEN' header, as these may indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003ePatch Wukong_HRM by updating to a version beyond commit 186115e.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect incoming traffic and block API requests missing the mandatory 'AUTH-TOKEN' header.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-11T03:58:00Z","date_published":"2026-10-11T03:58:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wukong-hrm-auth-bypass/","summary":"Wukong_HRM up to commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to access sensitive HR administrative API endpoints.","title":"Authentication Bypass in Wukong_HRM ParamAspect","url":"https://feed.craftedsignal.io/briefs/2026-10-wukong-hrm-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Wukong_HRM","version":"https://jsonfeed.org/version/1.1"}