CVE-2026-90499 | lenve vhr 1.0-SNAPSHOT Password Update /hr/pass HrInfoController.updatePass hrid improper authorization

SecurityVulns

A vulnerability described as problematic has been identified in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization.

This vulnerability is identified as CVE-2026-90499. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More