Authorization Flaw in vhr Product by Lenve
CVE-2026-85182
7.7HIGH
What is CVE-2026-85182?
A significant authorization flaw exists within the vhr product that allows authenticated attackers to change passwords of other users' accounts. By sending a PUT request to /hr/pass with a target account ID and the current password of that account, an attacker can arbitrarily alter the password without proper authorization. This vulnerability leads to potential account takeovers and compromises user data safety.
Affected Version(s)
vhr 0 <= 03abbd35af24e55368ce4e09f4038dc2aba3ff5f
