Wukong_HRM ParamAspect Auth Bypass CVE-2026-108707 Risks Remote HR Data Manipulation and Deletion
A critical flaw in the ParamAspect component allows unauthenticated users to access all HR API endpoints by omitting a specific header.

Key points
- CVE-2026-108707 is rated CVSS 9.3 Critical due to full administrative access without credentials.
- The vulnerability exists in the ParamAspect component of Wukong_HRM through commit 186115e.
- Attackers can read, modify, or delete employee records, payslips, and salary history remotely.
Wukong_HRM contains a critical authentication bypass vulnerability within its ParamAspect component, identified as CVE-2026-108707. This flaw allows unauthenticated attackers to access every HRM API endpoint by simply omitting the AUTH-TOKEN header from their requests. The issue grants immediate HR administrator privileges without requiring valid credentials.
Root cause
The vulnerability stems from improper input validation in the ParamAspect module, classified under CWE-287. According to the NVD record, the system fails to enforce authentication checks when the AUTH-TOKEN header is absent. This logical error permits direct access to protected resources. The flaw affects Wukong_HRM versions up to commit 186115e1a5a0b827ad9596ff8c2f3a876fb0cc55.
Attack path
An attacker sends an HTTP request to any HRM API endpoint without including the AUTH-TOKEN header. The ParamAspect component processes this request as valid, granting full administrative access. Attackers can then read sensitive data such as payslips and salary history. They can also download attachments, modify company-wide HR records, or delete employee data entirely.
Affected versions
- WuKongOpenSource Wukong_HRM versions prior to and including commit 186115e1a5a0b827ad9596ff8c2f3a876fb0cc55 are affected.
- The vulnerability is present in the ParamAspect component of these builds.
- No later versions are mentioned in the current advisory as being patched or safe.
Mitigation
- Restrict network access to Wukong_HRM API endpoints using firewalls or web application firewalls.
- Monitor logs for API requests that lack the AUTH-TOKEN header, as this indicates exploitation attempts.
- Ensure strict access controls are applied at the network perimeter to prevent unauthorised external connections.
- Verify that all internal systems interacting with the HRM API enforce additional authentication layers.
What to do and how to stay safe: Wukong_HRM
- Audit firewall rules to block unauthorised external access to HR management API endpoints.
- Monitor server logs for requests missing the AUTH-TOKEN header to detect active exploitation attempts.
- Implement network segmentation to isolate HR systems from general corporate networks.
- Review access controls for all administrative interfaces to ensure secondary verification is required.
Step-by-step guide: Out-of-band patches: what small businesses need to know
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-108707?
The National Vulnerability Database rates CVE-2026-108707 as CVSS 9.3 Critical.
Which component is responsible for this authentication bypass?
The vulnerability is located in the ParamAspect component of Wukong_HRM.
How do attackers exploit this flaw?
Attackers exploit the flaw by omitting the AUTH-TOKEN header when calling HRM API endpoints.



