SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91770

MEDIUM · CVSS 6.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IceHRM versions prior to 36.0.0 are vulnerable due to inadequate validation of employee ownership on multiple REST sub-resource endpoints, enabling authenticated users to access and read sensitive HR records of any colleague. This flaw allows attackers to manipulate employee IDs to retrieve confidential information related to skills, education, certifications, and attendance. Organizations using affected versions should prioritize patching to protect employee privacy and maintain compliance with data protection regulations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91770
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.