MEDIUMVulnerability

CVE-2026-90501

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
MEDIUM
score
6.3
cve_id
CVE-2026-90501
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-13T08:16:27.017
last_modified
2026-09-16T14:17:13.500

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Privilege Management
[Weakness]Incorrect Privilege Assignment

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90501 — Ninja Signal Threat Intelligence | Ninja Signal