Junglewise Threat Intelligence

CVE-2026-90499: lenve vhr password change improper authorization

CVE-2026-90499 · Severity: medium · CVSS 5.4 · Published 2026-09-13

Technologies: Lenve Vhr. Vendors: Lenve.

Executive brief

lenve vhr is a Human Resources management system used by organizations to manage employee information. The password change functionality contains an authorization bypass flaw that allows any authenticated user to change another employee's password if they know the victim's old password, potentially leading to account takeover. This risk is heightened when default or weak passwords are in use across the organization.

Technical details

The vulnerability is an improper authorization (CWE-285) flaw in the HrInfoController.updatePass() function of the /hr/pass endpoint. The root cause is that the hrid (Human Resource ID) parameter submitted by the client is not validated against the authenticated user's actual identity—there is no check to ensure hrid matches the current user's ID. An authenticated attacker can change any user's password by crafting a PUT request with a target hrid, the victim's old password, and a new password. The vulnerability requires network access and valid authentication credentials, but can be exploited by any logged-in user to compromise any other user account.

Affected products

  • lenve vhr 1.0-SNAPSHOT

Timeline

  • 2026-09-13: disclosed
  • exploited: Exploit has been released to the public

References

Related threats