PT-2026-85041 · Vhr · Vhr

·

CVE-2026-85182

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vhr versions prior to commit 03abbd3
Description An authorization failure occurs when the system does not verify if the account ID provided in a request belongs to the authenticated user. This allows authenticated attackers to change passwords for arbitrary accounts by providing a target account ID and the current password of that account in the request body of the 'PUT /hr/pass' endpoint.
Recommendations Update vhr to a version beyond commit 03abbd3. As a temporary mitigation, restrict access to the 'PUT /hr/pass' endpoint.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85182

Affected Products

Vhr