Authorization Bypass in vhr HR Management Software
CVE-2026-85214

7.2HIGH

Key Information:

Vendor

Lenve

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85214?

The vhr HR management software lacks proper user authorization checks in the PUT /hr/info endpoint. This vulnerability allows authenticated users to modify any HR profile by simply supplying the profile ID in the request body. As a consequence, attackers can alter critical information such as names and addresses of other users, including the ability to disable accounts, even for administrators. Such actions can lead to denial of service, compromising the integrity and functionality of the HR system.

Affected Version(s)

vhr 0 <= 03abbd35af24e55368ce4e09f4038dc2aba3ff5f

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.