PatchSiren

gamonoid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gamonoid CVE published 2026-09-15

CVE-2026-91770

CVE-2026-91770 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T02:16:49.517Z and has not been modified since then. IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. This vulnerability allows attackers to access sensitive personnel data by substituting a [truncated]