Sceawere

Vulnerability Detail

CVE-2026-94149UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Omega HRM Improper Resource Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
Omega Solution
Product
HRM OS
Attack Type
Improper Control of Resource Identifiers
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-21T08:16:39.190Z",
  "pubdate": "2026-09-21T08:16:39.190Z",
  "executiveSummary": "Omega Solution HRM OS is susceptible to a vulnerability involving improper control of resource identifiers within the Role Permission Retrieval Endpoint.\nThe flaw stems from insecure handling of the 'roleId' argument within the '/role-permission/permission' function.\nThis vulnerability allows remote, unauthenticated attackers to manipulate resource identifiers, potentially leading to unauthorized access to sensitive role-based permission data.\nThe risk is elevated due to the public availability of an exploit, combined with the vendor's failure to respond to initial disclosure efforts, leaving affected systems at high risk of unauthorized data retrieval.\nOrganizations utilizing Omega Solution HRM OS versions up to 20260717 are exposed to this risk and should implement immediate defensive measures to restrict access to the affected endpoint.",
  "technicalDetails": "The vulnerability resides in the Role Permission Retrieval Endpoint of Omega Solution HRM OS, specifically within the '/role-permission/permission' file.\nThe root cause is identified as an improper control of resource identifiers, where the application fails to adequately validate or sanitize the 'roleId' argument provided by the user in the request.\nThe exploitation flow begins with a remote attacker sending a crafted request to the '/role-permission/permission' endpoint.\nBy manipulating the 'roleId' parameter, an attacker can bypass intended access controls that restrict permission information to specific, authorized roles.\nBecause the server-side logic does not properly verify that the requester is authorized to access the requested resource identifier, the application processes the tainted 'roleId' and returns sensitive role-permission mapping data corresponding to the manipulated ID.\nThis mechanism is symptomatic of an Insecure Direct Object Reference (IDOR) or a similar path traversal-style flaw in the logic handling resource IDs, allowing for the enumeration or unauthorized retrieval of data mapped to specific roles within the HRM system.\nThe exploitation does not appear to require complex authentication bypasses if the endpoint is exposed, as the flaw resides in the input handling of the role identification logic itself.\nThe impact of a successful exploit is the unauthorized disclosure of role-permission configurations, which provides an attacker with critical insights into the internal security architecture of the HRM software.\nThis information can subsequently be utilized to identify further attack vectors, such as privilege escalation or lateral movement within the application environment.\nAffected versions include all iterations of Omega Solution HRM OS up to and including 20260717.\nGiven the public availability of the exploit, the barrier to entry for potential attackers is significantly low, requiring minimal technical sophistication to successfully query unauthorized permission data."
}
CVE-2026-94149: Omega HRM Improper Resource Control (MEDIUM Severity, CVSS: 4.3) | Sceawere