Executive brief
A security vulnerability has been identified in MeWare PDKS, a software system used by organizations to manage employee attendance and access control. An attacker with basic user access can bypass security checks to gain unauthorized privileges, potentially allowing them to view or modify sensitive personnel records and attendance data. This could lead to unauthorized administrative actions or the manipulation of payroll-related information.
Technical details
MeWare PDKS is affected by an Insecure Direct Object Reference (IDOR) vulnerability, specifically classified as CWE-639 (Authorization Bypass Through User-Controlled Key). The flaw exists because the application fails to properly validate that the user has the necessary permissions to access or modify an object identified by a user-supplied key or parameter. An attacker with low-privileged network access can exploit this by manipulating these keys to access data or functions belonging to other users or administrators. The vulnerability is present in versions ranging from V16.20200313 to VMYR_3.5.2025117. A patch is available in version VMYR_3.5.2025117.
Affected products
- MeWare Software Development Inc. PDKS (Personnel Attendance Control System) V16.20200313 to VMYR_3.5.2025117
Timeline
- 2026-04-30: disclosed
- 2026-04-30: advisory