PatchSiren cyber security CVE debrief
CVE-2026-94151 Omega Solution CVE debrief
A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendor
- Omega Solution
- Product
- HRM OS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for HRM OS deployments should assess the potential impact of this vulnerability on their systems and prioritize verification and mitigation efforts. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and implement compensating controls to
Why it matters
This vulnerability allows for missing authentication via the Role Permission API in Omega Solution HRM OS up to 20260717, which could be used for attacks. Defenders should prioritize verification and mitigation efforts.
- Verify the presence of this vulnerability in HRM OS deployments
- Assess the potential impact of missing authentication on HRM OS systems
- Implement compensating controls to mitigate the vulnerability
Technical summary
The vulnerability affects an unknown function of the file /role-permission/permission of the component Role Permission API in Omega Solution HRM OS up to 20260717. Executing a manipulation of the argument roleId can lead to missing authentication. This could be used for attacks. The exploit has been made available to the public. Defenders should prioritize verifying the presence of this vulnerability in their HRM OS deployments and assess the potential impact of missing authentication on their systems. The vendor was contacted early about this disclosure but did not respond in any way.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their HRM OS deployments and assess the potential impact of missing authentication on their systems.
Recommended defensive actions
- Verify the presence of this vulnerability in HRM OS deployments
- Assess the potential impact of missing authentication on HRM OS systems
- Implement compensating controls to mitigate the vulnerability
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide information about the vulnerability, but the vendor did not respond to the disclosure. The exploit has been made available to the public, but there is no information on its usage in attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94151 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94151
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94151 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94151
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/4m3rr0r/PoCVulDb/issues/22
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-94151
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/894312
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408065
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408065/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.