Authorization Flaw in vhr Product by Lenve
CVE-2026-85182

7.7HIGH

Key Information:

Vendor

Lenve

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85182?

A significant authorization flaw exists within the vhr product that allows authenticated attackers to change passwords of other users' accounts. By sending a PUT request to /hr/pass with a target account ID and the current password of that account, an attacker can arbitrarily alter the password without proper authorization. This vulnerability leads to potential account takeovers and compromises user data safety.

Affected Version(s)

vhr 0 <= 03abbd35af24e55368ce4e09f4038dc2aba3ff5f

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.