在 Omega Solution HRM OS 截至 20260717 版本中存在一个已识别的漏洞。该漏洞影响 Role Permission API 组件中 /role-permission/permission 文件的某个未知功能。通过操纵 roleId 参数,可能导致认证缺失漏洞。该攻击可远程发起。漏洞利用方式已公开,可被用于发起攻击。厂商已就此次披露事宜提前联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Omega Solution | HRM OS | 20260717 |
cpe:2.3:a:omega_solution:hrm_os:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94149 | 4.3 MEDIUM | Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection |
| CVE-2026-94152 | 4.3 MEDIUM | Omega Solution FBP Fulfillment by People User Profile API user authorization |
| CVE-2026-94150 | 2.4 LOW | Omega Solution HRM OS SVG File Upload view cross site scripting |
No comments yet