www.vulncheck.com High-Risk CVE-2026-108708 in Wukong_HRM Exposes Sensitive Employee Data
Article Content
- •CVE-2026-108708 allows unauthorized access to sensitive employee data.
- •Vulnerability affects self-hosted Wukong_HRM systems, especially if internet-accessible.
- •Proof-of-concept code is available, but active exploitation is unconfirmed.
A missing authorization vulnerability in Wukong_HRM, identified as CVE-2026-108708, allows low-privileged employees to access sensitive payroll information, including payslips and bank details. The flaw arises from commit 186115e, where EmployeeAspect improperly grants HR administrator roles to all callers, and EmployeeUtil fails to restrict data access. Organizations using self-hosted HR platforms are at high risk, particularly if the service is internet-accessible. Proof-of-concept material exists, but active exploitation status remains unknown. Immediate action is recommended to mitigate potential data breaches and unauthorized changes. Security teams should review access logs and restrict network access to trusted users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-108708 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who is affected by CVE-2026-108708?
What should organizations do to mitigate this vulnerability?
Is there any active exploitation of this vulnerability?
Continue Reading
JeecgBoot 3.9.5 Vulnerabilities: Missing Authorization Issues Two vulnerabilities have been identified in JeecgBoot versions up to 3.9.5, specifically in the saveDeptRolePermission and sysTenantPassapply endpoints. These vulnerabilities involve missing authorization checks, allowing unauthorized users to access sensitive functionalities. The issues are categorized under CWE-862…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…