CVE-2026-91770
nicheIDOR in IceHRM before 36.0.0 Lets Employees Read Any Colleague's HR Records
IceHRM versions before 36.0.0 fail to validate that the requesting employee owns the record being accessed on seven REST sub-resource endpoints, a broken object-level authorization flaw (CWE-639). Any authenticated employee can substitute another worker's employee ID in requests to the skill, education, certification, language, leave, attendance, and status endpoints and retrieve that colleague's HR data. This exposes sensitive personnel information such as leave histories, attendance records, certifications, and other profile details to any insider with a basic account. Organizations running self-hosted IceHRM instances older than 36.0.0 (and hosted tenants not yet patched) are affected. There is no known public proof of concept, the issue is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported, though the flaw is trivially exploitable by any low-privilege employee.
What to do: Upgrade to IceHRM 36.0.0 or later, which adds employee-ownership validation on the affected REST endpoints. If patching is delayed, review API/application logs for requests where one employee ID accessed another employee's skill, education, certification, language, leave, attendance, or status records, and tighten access so only trusted internal accounts can reach the API. Because exploitation leaves atypical read patterns rather than malware, log review is the main detection avenue.
| IceHRM | before 36.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.