External risk intelligence

Wukong HRM Authentication Bypass Exposes Sensitive HR Data

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-108707

Wukong_HRM is a Human Resource Management application. HRM systems are commonly deployed as web applications intended for employee and administrator access, frequently requiring network or internet connectivity to facilitate remote access for organizational workflows.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Wukong_HRM, specifically within ParamAspect, allows unauthorized access to sensitive HR data. This issue enables unauthenticated attackers to bypass security controls and access employee personal information, salary details, and company records. The main concern is confirming relevance and exposure to this type of Human Resource Management system.

  • Bypasses security to access HR data.
  • Impacts systems managing employee personal information.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication to access the Wukong HRM application by simply not providing an authentication token. This allows them to interact with any API endpoint, potentially leading to unauthorized access to sensitive HR data and the ability to modify or delete critical company information.

  • No authentication token required.
  • Any HRM API endpoint can be called.
  • Unauthorized access to HR data.

Live Threat

Current exploitation, exposure, and threat context

An authentication bypass vulnerability in Wukong_HRM could allow unauthenticated attackers to access all HRM API endpoints. This could lead to unauthorized access to sensitive employee data, including payslips, salary history, and personal information, as well as the ability to download attachments and modify or delete company HR records.

  • Sensitive HR and employee data.
  • Unauthenticated API access.
  • Unauthorized data modification or deletion.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Wukong_HRM application's authentication bypass vulnerability necessitates action from teams managing HR systems and the underlying infrastructure. The first step is to locate all Wukong_HRM instances, assess their exposure and criticality, and identify the designated owner for remediation planning.

  • Identify Wukong_HRM instances and ownership.
  • Verify network exposure and business impact.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Wukong_HRM?

Wukong_HRM is a software application designed to manage Human Resource Management tasks. Organizations use it to centralize employee records, handle sensitive salary history, process payslips, and store various HR-related attachments.

How does CVE-2026-108707 affect security?

This vulnerability is an Improper Authentication weakness (CWE-287). It means the system's security checks fail to verify who is making a request. In this specific case, the software allows users to interact with its API without proving their identity, granting them administrative-level access.

Do I need an account to trigger this bug?

No. The vulnerability exists because the system incorrectly processes requests when the AUTH-TOKEN header is missing. Simply omitting this token allows an unauthorized user to reach API endpoints. This flaw is not triggered by authenticated users but rather by the lack of required authentication data in the request.

Is my Wukong_HRM instance at risk?

According to Halo Surface Signal, Wukong_HRM is a web-based tool often connected to networks to support remote employee workflows. If your instance is internet-facing, it is more easily reachable by external parties. You should assess whether your specific deployment is accessible from outside your internal network.

How should I respond to this vulnerability?

Begin by creating a complete inventory of all Wukong_HRM instances running in your environment. Once identified, confirm which instances are accessible over the network and determine who is responsible for their maintenance. Use this information to prioritize and coordinate a remediation plan with the system owners.

References