Junglewise Threat Intelligence

CVE-2026-94151: Omega Solution HRM OS missing authentication in role permission API

CVE-2026-94151 · Severity: medium · CVSS 5.3 · Published 2026-09-21

Executive brief

Omega Solution HRM OS is a human resources management system that controls employee roles and permissions. An attacker can access the role permission endpoint without logging in and retrieve complete permission sets for any role, allowing them to map the application's authorization structure and plan more sophisticated attacks.

Technical details

The Role Permission API endpoint GET /role-permission/permission fails to enforce authentication before disclosing authorization data. An unauthenticated attacker can supply a valid roleId parameter and retrieve the complete permission set (including 260+ permissions) associated with that role. This allows enumeration of privileged roles and the full authorization model of the application without requiring valid credentials.

Affected products

  • Omega Solution HRM OS up to 20260717

Timeline

  • 2026-09-21: disclosed
  • 2026-07-17: other: Vendor contacted early but did not respond

References

Related threats