CVE advisoryCRITICAL
CVE-2026-108707
Wukong HRM Authentication Bypass Exposes Sensitive HR Data
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Wukong_HRM has an authentication bypass vulnerability that allows unauthenticated attackers to access all API endpoints, potentially exposing sensitive HR data such as payslips and employee personal information. This could enable attackers to modify or delete company HR records, making it crucial to confirm the relevan