Sceawere
Vulnerability Detail
CVE-2026-94151UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Omega HRM Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 5h ago
- Vendor
- Omega Solution
- Product
- HRM OS
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-21T09:17:06.567Z",
"pubdate": "2026-09-21T09:17:06.567Z",
"executiveSummary": "A critical security weakness has been identified in the Role Permission API of Omega Solution HRM OS versions up to 20260717.\nThe vulnerability is classified as a missing authentication flaw, allowing unauthorized actors to manipulate system permissions.\nSuccessful exploitation enables remote attackers to bypass established security controls without requiring valid authentication credentials.\nThe vulnerability originates from improper handling of the 'roleId' argument within the '/role-permission/permission' endpoint.\nGiven that exploit code is publicly available and the vendor has remained unresponsive, the risk to organizations deploying this software is severe.\nPotential impacts include unauthorized elevation of privilege, unauthorized access to sensitive HRM data, and complete compromise of administrative roles.\nThis vulnerability is remotely exploitable, requiring no prior system access or session authentication to execute.",
"technicalDetails": "The vulnerability resides within the Role Permission API component of Omega Solution HRM OS, specifically targeting the '/role-permission/permission' endpoint.\nThe root cause of the vulnerability is the failure of the application to properly enforce authentication checks or validate the 'roleId' argument during a request processing sequence.\nWhen a request is directed to the '/role-permission/permission' file, the application processes the 'roleId' parameter without verifying if the requesting user possesses the requisite administrative authorization to query or modify permission configurations.\nThe attack flow proceeds as follows: An unauthenticated remote attacker crafts an HTTP request targeting the vulnerable endpoint. By manipulating the 'roleId' argument within the query string or request body, the attacker forces the backend function to process the request as if it originated from an authorized session.\nBecause the server-side logic fails to validate the caller's session state against the provided 'roleId', the API returns the requested permission data or executes the associated configuration logic without restriction.\nThe lack of integrity verification on the 'roleId' parameter allows an adversary to enumerate roles or modify permission structures globally across the HRM installation.\nThis represents a failure in the application's authorization framework, where the 'roleId' parameter effectively serves as an insecure direct object reference (IDOR) that bypasses authentication entirely.\nThe impact is significant: by successfully bypassing authentication, an attacker can gain unauthorized insights into the organization's role-based access control (RBAC) model, escalate their own privileges by modifying permission sets, or deny service by corrupting role mappings.\nThe vulnerability affects all Omega Solution HRM OS versions up to and including 20260717. As the exploit is public, the attack surface is active and requires immediate defensive attention."
}