CVE-2026-47094: Authorization Bypass Through User-Controlled Key in SIMAC MyPHR
SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.
AI Analysis
Technical Summary
CVE-2026-47094 is an IDOR vulnerability in SIMAC MyPHR 1.1 that enables authenticated attackers to bypass authorization by manipulating the employee update endpoint. The vulnerability arises from the lack of server-side validation of ownership, allowing attackers to specify arbitrary employee identifiers in PUT requests to update employee records. This can lead to account takeover, enumeration of employee records, and unauthorized access to sensitive personal data such as pay bulletins.
Potential Impact
Exploitation of this vulnerability allows attackers with valid authentication to take over other employee accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins. This poses a significant risk to confidentiality and integrity of employee data within the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the employee update endpoint to trusted users only and monitor for suspicious activity involving modification of employee records.
CVE-2026-47094: Authorization Bypass Through User-Controlled Key in SIMAC MyPHR
Description
SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.
CVSS v4.0
Score 8.7high
Affected software
SIMAC
MyPHR
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-47094 is an IDOR vulnerability in SIMAC MyPHR 1.1 that enables authenticated attackers to bypass authorization by manipulating the employee update endpoint. The vulnerability arises from the lack of server-side validation of ownership, allowing attackers to specify arbitrary employee identifiers in PUT requests to update employee records. This can lead to account takeover, enumeration of employee records, and unauthorized access to sensitive personal data such as pay bulletins.
Potential Impact
Exploitation of this vulnerability allows attackers with valid authentication to take over other employee accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins. This poses a significant risk to confidentiality and integrity of employee data within the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the employee update endpoint to trusted users only and monitor for suspicious activity involving modification of employee records.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-05-18T19:22:26.747Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aaad61e55bf5e2cf5f51402
Added to database: 09/16/2026, 17:47:10 UTC
Last enriched: 09/16/2026, 18:01:52 UTC
Last updated: 09/17/2026, 03:02:11 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.