PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94151 Omega Solution CVE debrief

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Vendor
Omega Solution
Product
HRM OS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-21
Advisory published
2026-09-21
Advisory updated
2026-09-21

Who should care

Defenders responsible for HRM OS deployments should assess the potential impact of this vulnerability on their systems and prioritize verification and mitigation efforts. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and implement compensating controls to

Why it matters

This vulnerability allows for missing authentication via the Role Permission API in Omega Solution HRM OS up to 20260717, which could be used for attacks. Defenders should prioritize verification and mitigation efforts.

  • Verify the presence of this vulnerability in HRM OS deployments
  • Assess the potential impact of missing authentication on HRM OS systems
  • Implement compensating controls to mitigate the vulnerability

Technical summary

The vulnerability affects an unknown function of the file /role-permission/permission of the component Role Permission API in Omega Solution HRM OS up to 20260717. Executing a manipulation of the argument roleId can lead to missing authentication. This could be used for attacks. The exploit has been made available to the public. Defenders should prioritize verifying the presence of this vulnerability in their HRM OS deployments and assess the potential impact of missing authentication on their systems. The vendor was contacted early about this disclosure but did not respond in any way.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their HRM OS deployments and assess the potential impact of missing authentication on their systems.

Recommended defensive actions

  • Verify the presence of this vulnerability in HRM OS deployments
  • Assess the potential impact of missing authentication on HRM OS systems
  • Implement compensating controls to mitigate the vulnerability
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide information about the vulnerability, but the vendor did not respond to the disclosure. The exploit has been made available to the public, but there is no information on its usage in attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94151 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94151

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94151 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94151

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.