PatchSiren

Omega Solution CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Omega Solution CVE published 2026-09-21

CVE-2026-94152

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025, impacting an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Defenders should assess exposure and prioritize verification [truncated]

MEDIUM Omega Solution CVE published 2026-09-21

CVE-2026-94151

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacte [truncated]

LOW Omega Solution CVE published 2026-09-21

CVE-2026-94150

A security flaw has been discovered in Omega Solution HRM OS up to 20260717, impacting an unknown function of the file /media/view/ of the component SVG File Upload. This results in cross-site scripting when a manipulation is performed. The attack can be initiated remotely. The CVE record and NVD entry provide limited information about the vulnerability. The vendor was contacted but did not respond. Defen [truncated]

LOW Omega Solution CVE published 2026-09-21

CVE-2026-94149

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers. The attack can be launched remotely. This vulnerability has a significant impact on HRM OS deployments, and [truncated]