MEDIUM
CVE-2026-90501
CVSS
6.3
Description
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Weakness (CWE)
CWE-266
Incorrect Privilege Assignment
CWE-269
Improper Privilege Management
EPSS Score
0.2%
Probability of exploitation in next 30 days
10.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.