Improper Authorization Flaw in lenve vhr Product by Vendor Lenve
CVE-2026-90499
Key Information:
Badges
What is CVE-2026-90499?
A security flaw has been identified in the lenve vhr 1.0-SNAPSHOT product, specifically in the Password Update Handler during the execution of the HrInfoController.updatePass function. This vulnerability arises from improper handling of the hrid argument, enabling potential remote exploitation through unauthorized access. An exploit has been made publicly available, placing users at increased risk. Notifications were sent to the vendor regarding this issue, but no response was received, highlighting the urgent need for users to assess their security posture.
Affected Version(s)
vhr 1.0-SNAPSHOT
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
