CVE-2026-85214

Source
https://cve.org/CVERecord?id=CVE-2026-85214
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85214.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85214
Published
2026-09-03T14:12:24Z
Modified
2026-10-08T02:52:16Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite
Details

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85214.json"
}
References

Affected packages

Git / github.com/lenve/vhr

Affected ranges

Type
GIT
Repo
https://github.com/lenve/vhr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Affected versions

Other
v20180107
v20180110
v20180112
v20180115
v20180116
v20180117
v20180119
v20180125
v20180126
v20180202
v20180205
v20191222

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85214.json"