PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91770 gamonoid CVE debrief

CVE-2026-91770 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T02:16:49.517Z and has not been modified since then. IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. This vulnerability allows attackers to access sensitive personnel data by substituting arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints.

Vendor
gamonoid
Product
icehrm
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-23
Advisory published
2026-09-15
Advisory updated
2026-09-23

Who should care

HR personnel, administrators, and IT staff responsible for managing employee data and ensuring the security of HR systems should assess their exposure to this vulnerability and take necessary actions to prevent unauthorized access to sensitive personnel data.

Why it matters

CVE-2026-91770 allows authenticated employees to read any colleague's HR records due to a lack of validation of employee ownership on seven REST sub-resource endpoints in IceHRM versions before 36.0.0.

  • Verify employee data access controls to prevent unauthorized access to sensitive personnel data.
  • Restrict access to HR records based on employee roles and responsibilities.
  • Monitor HR records for suspicious activity.

Technical summary

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. The vulnerable endpoints include skill, education, certification, language, leave, attendance, and status. This vulnerability can be exploited by substituting arbitrary employee IDs, potentially leading to unauthorized access to sensitive personnel data. HR personnel and administrators should prioritize verifying employee data access controls and upgrading to IceHRM version 36.0.0 or later.

Defensive priority

HR personnel and administrators should prioritize verifying employee data access controls and upgrading to IceHRM version 36.0.0 or later.

Recommended defensive actions

  • Verify employee data access controls to prevent unauthorized access to sensitive personnel data.
  • Upgrade to IceHRM version 36.0.0 or later to fix the vulnerability.
  • Monitor HR records for suspicious activity.
  • Restrict access to HR records based on employee roles and responsibilities.
  • Perform a thorough review of HR records for potential unauthorized access.
  • Implement additional security measures to detect and prevent similar vulnerabilities.
  • Conduct regular security audits to identify and address potential vulnerabilities.

Evidence notes

The CVE record and source references indicate that IceHRM versions before 36.0.0 are vulnerable to unauthorized access to employee HR records. The vulnerability is due to a lack of validation of employee ownership on seven REST sub-resource endpoints.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91770 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91770

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91770 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91770

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.