CVE-2026-90501 Details
Description
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing improper privilege management has been identified in Lenve VHR version 1.0-SNAPSHOT. The issue arises in the HrInfoController.updateHr function, where the HrMapper.xml file is manipulated by the Password argument. This vulnerability can be exploited remotely by low-privilege users to escalate privileges.
To address this vulnerability, update the application to bind user information updates to the session user ID, and restrict the password, username, and enabled fields from being modified through the '/hr/info' endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ArrestX/vhr-advisories/blob/main/advisories/VHR-VULN-001-mass-assignment-privesc.md | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/cve/CVE-2026-90501 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/892904 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403089 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403089/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenve vhr | 1.0-SNAPSHOT |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion