Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108707— Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect

Quick assessment

Affected
WuKongOpenSource Wukong_HRM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wukong_HRM 在提交 186115e 中存在一个由 ParamAspect 引发的身份验证绕过漏洞,攻击者可以通过省略 AUTH-TOKEN 头信息,以未授权的方式访问 HRM 的所有 API 端点。利用该漏洞,攻击者可获得 HR 管理员权限,从而读取工资单、薪资历史及员工个人数据,下载附件,并修改或删除公司范围内的 HR 记录。

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108707

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect
Source: CVE Program / CVE List V5
Vulnerability Description
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WuKongOpenSource Wukong_HRM 0 ~ 186115e1a5a0b827ad9596ff8c2f3a876fb0cc55 -

II. Public POCs for CVE-2026-108707

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108707

请登录查看更多情报信息。

Other References for CVE-2026-108707 (6)

Same Patch Batch · WuKongOpenSource · 2026-10-11 · 3 CVEs total

CVE-2026-108708 8.8 HIGH Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUti
CVE-2026-108689 5.4 MEDIUM Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST

IV. Related Vulnerabilities

V. Comments for CVE-2026-108707

No comments yet


Leave a comment