---
id: CVE-2026-91770
title: >-
  IceHRM before 36.0.0 fails to validate employee ownership on seven REST
  sub-resource endpoints, allowing authenticated employees to read any
  colleague's HR records
summary: >-
  IceHRM before 36.0.0 fails to validate employee ownership on seven REST
  sub-resource endpoints, allowing authenticated employees to read any
  colleague's HR records. Attackers can substitute arbitrary employee IDs in
  skill, education, cer…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: gamonoid
product: icehrm
affected:
  - icehrm < 36.0.0
published: '2026-09-15'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:47.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91770'
references:
  - url: 'https://github.com/gamonoid/icehrm'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gamonoid/icehrm/blob/e75ed7e45de41f7b2b3ea319d9406514afa2bf29/core/src/Employees/Rest/EmployeeSkillsRestEndPoint.php#L20-L51
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gamonoid/icehrm/commit/19674f29a0591c985712dc4a5c841e21d7dbf971
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gamonoid/icehrm/issues/375'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gamonoid/icehrm/releases/tag/v36.0.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/icehrm-before-36.0.0-broken-access-control-via-employee-id
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gamonoid/icehrm/issues/375'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00454
epssPercentile: 0.36769
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:46:38.392085Z'
ingestedAt: '2026-09-15T02:19:07.441Z'
---

## Overview

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
