Skip to content
High-Risk CVE-2026-108708 in Wukong_HRM Exposes Sensitive Employee Data

High-Risk CVE-2026-108708 in Wukong_HRM Exposes Sensitive Employee Data

First seen 11 Oct 2026, 10:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •CVE-2026-108708 allows unauthorized access to sensitive employee data.
  • •Vulnerability affects self-hosted Wukong_HRM systems, especially if internet-accessible.
  • •Proof-of-concept code is available, but active exploitation is unconfirmed.

A missing authorization vulnerability in Wukong_HRM, identified as CVE-2026-108708, allows low-privileged employees to access sensitive payroll information, including payslips and bank details. The flaw arises from commit 186115e, where EmployeeAspect improperly grants HR administrator roles to all callers, and EmployeeUtil fails to restrict data access. Organizations using self-hosted HR platforms are at high risk, particularly if the service is internet-accessible. Proof-of-concept material exists, but active exploitation status remains unknown. Immediate action is recommended to mitigate potential data breaches and unauthorized changes. Security teams should review access logs and restrict network access to trusted users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-11
CVE-2026-108708 published
Wukong_HRM vulnerability disclosed, allowing unauthorized access to sensitive employee data.
Redpacketsecurity
2026-10-11
Vulnerability details released
Details on missing authorization in Wukong_HRM commit 186115e published, highlighting risks.
www.vulncheck.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-108708 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who is affected by CVE-2026-108708?
Organizations using self-hosted Wukong_HRM systems, especially those accessible over the internet.
What should organizations do to mitigate this vulnerability?
Identify affected deployments, apply vendor-confirmed fixes, and restrict network access to trusted users.
Is there any active exploitation of this vulnerability?
Currently, active exploitation status is unknown, but proof-of-concept material exists.