CVE-2026-85182

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 15:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-85182

Mitre link : CVE-2026-85182

CVE.ORG link : CVE-2026-85182


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key