Junglewise Threat Intelligence

CVE-2026-15804: MetaGuru HCM SQL injection in specific parameters

CVE-2026-15804 · Severity: high · CVSS 8.8 · Published 2026-07-15

Executive brief

MetaGuru HCM, a human capital management system used for HR and payroll operations, contains a security flaw that allows authorized users to execute unauthorized database commands. An attacker with basic user credentials could exploit this to view, modify, or delete sensitive employee information and organizational data. This could lead to significant data breaches, loss of data integrity, or disruption of HR services.

Technical details

A SQL injection vulnerability exists in MetaGuru HCM versions 7 (prior to 7.5.3) and 8 (prior to 8.1.7.1). The flaw is located in the handling of specific parameters where user input is not properly neutralized before being used in SQL queries (CWE-89). An authenticated remote attacker can exploit this by sending crafted SQL commands to the server. Successful exploitation allows the attacker to bypass application logic, read sensitive database records, modify data, or perform administrative operations on the database. The vulnerability is addressed in versions 7.5.3 and 8.1.7.1.

Affected products

  • MetaGuru HCM 7 before 7.5.3, 8 before 8.1.7.1

Timeline

  • 2026-07-15: advisory: Initial disclosure by TWCERT/CC and NVD
  • 2026-07-15: patched: Fixes released in versions 7.5.3 and 8.1.7.1

References