Authorization Bypass in vhr HR Management Software
CVE-2026-85214
7.2HIGH
What is CVE-2026-85214?
The vhr HR management software lacks proper user authorization checks in the PUT /hr/info endpoint. This vulnerability allows authenticated users to modify any HR profile by simply supplying the profile ID in the request body. As a consequence, attackers can alter critical information such as names and addresses of other users, including the ability to disable accounts, even for administrators. Such actions can lead to denial of service, compromising the integrity and functionality of the HR system.
Affected Version(s)
vhr 0 <= 03abbd35af24e55368ce4e09f4038dc2aba3ff5f
