CVE-2026-94149 | Omega Solution HRM OS up to 20260717 Role Permission Retrieval Endpoint permission roleId resource injection
A vulnerability was found in Omega Solution HRM OS up to 20260717 and classified as problematic. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers.
This vulnerability is uniquely identified as CVE-2026-94149. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More