---
id: CVE-2026-94149
title: A vulnerability was identified in Omega Solution HRM OS up to 20260717
summary: >-
  A vulnerability was identified in Omega Solution HRM OS up to 20260717. The
  affected element is an unknown function of the file
  /role-permission/permission of the component Role Permission Retrieval
  Endpoint. Such manipulation of the arg…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-99
vendor: Omega Solution
product: HRM OS
affected:
  - hrm_os 20260717
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94149'
references:
  - url: 'https://github.com/4m3rr0r/PoCVulDb/issues/20'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94149'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894307'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408063'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408063/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00221
epssPercentile: 0.12937
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T10:23:46.308844Z'
ingestedAt: '2026-09-21T08:33:58.337Z'
---

## Overview

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
