CVE-2026-47094
—IDOR Account Takeover in SIMAC MyPHR 1.1
SIMAC MyPHR 1.1 is vulnerable to an insecure direct object reference (IDOR, CWE-639) because the employee update endpoint does not validate server-side that the authenticated user owns the record being modified. Any authenticated user can send a PUT request to that endpoint with an arbitrary employee identifier and a password value they control, allowing them to change other employees' passwords and take over their accounts. The same flaw also permits enumeration of employee records and retrieval of sensitive personally identifiable information, including private pay bulletins. Organizations running SIMAC MyPHR 1.1 with multiple employee accounts are affected, with a low barrier to exploitation (network-accessible, low privileges, no user interaction per the 8.7 CVSS 4.0 score). No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Contact the vendor for a patched release or an official fix, since no fixed version is stated in the available data. As an interim measure, audit application logs for PUT requests to the employee update endpoint referencing employee IDs other than the requester's own, and reset credentials for any accounts whose passwords may have been changed unexpectedly. Ensure employee accounts use strong, unique passwords to limit the impact of account takeover until server-side ownership validation is fixed.
| SIMAC MyPHR | 1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.