PatchSiren cyber security CVE debrief
CVE-2026-91770 gamonoid CVE debrief
CVE-2026-91770 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T02:16:49.517Z and has not been modified since then. IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. This vulnerability allows attackers to access sensitive personnel data by substituting arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints.
- Vendor
- gamonoid
- Product
- icehrm
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-23
Who should care
HR personnel, administrators, and IT staff responsible for managing employee data and ensuring the security of HR systems should assess their exposure to this vulnerability and take necessary actions to prevent unauthorized access to sensitive personnel data.
Why it matters
CVE-2026-91770 allows authenticated employees to read any colleague's HR records due to a lack of validation of employee ownership on seven REST sub-resource endpoints in IceHRM versions before 36.0.0.
- Verify employee data access controls to prevent unauthorized access to sensitive personnel data.
- Restrict access to HR records based on employee roles and responsibilities.
- Monitor HR records for suspicious activity.
Technical summary
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. The vulnerable endpoints include skill, education, certification, language, leave, attendance, and status. This vulnerability can be exploited by substituting arbitrary employee IDs, potentially leading to unauthorized access to sensitive personnel data. HR personnel and administrators should prioritize verifying employee data access controls and upgrading to IceHRM version 36.0.0 or later.
Defensive priority
HR personnel and administrators should prioritize verifying employee data access controls and upgrading to IceHRM version 36.0.0 or later.
Recommended defensive actions
- Verify employee data access controls to prevent unauthorized access to sensitive personnel data.
- Upgrade to IceHRM version 36.0.0 or later to fix the vulnerability.
- Monitor HR records for suspicious activity.
- Restrict access to HR records based on employee roles and responsibilities.
- Perform a thorough review of HR records for potential unauthorized access.
- Implement additional security measures to detect and prevent similar vulnerabilities.
- Conduct regular security audits to identify and address potential vulnerabilities.
Evidence notes
The CVE record and source references indicate that IceHRM versions before 36.0.0 are vulnerable to unauthorized access to employee HR records. The vulnerability is due to a lack of validation of employee ownership on seven REST sub-resource endpoints.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91770 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91770
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91770 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91770
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/gamonoid/icehrm
-
Source reference
Unverified legacy reference
URL: https://github.com/gamonoid/icehrm/blob/e75ed7e45de41f7b2b3ea319d9406514afa2bf29/core/src/Employees/Rest/EmployeeSkillsRestEndPoint.php
-
Source reference
Unverified legacy reference
URL: https://github.com/gamonoid/icehrm/commit/19674f29a0591c985712dc4a5c841e21d7dbf971
-
Source reference
Unverified legacy reference
URL: https://github.com/gamonoid/icehrm/issues/375
-
Source reference
Unverified legacy reference
URL: https://github.com/gamonoid/icehrm/releases/tag/v36.0.0
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/icehrm-before-36.0.0-broken-access-control-via-employee-id
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.