Skip to main content
HIGH

CVE-2026-85182

vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change

CVSS v3

7.5

HIGH

EPSS Score

0.4 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.

Technical details

Published
2026-09-03
Last Modified
2026-09-03

Frequently asked questions

What is CVE-2026-85182?

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.

Is CVE-2026-85182 actively exploited?

A proof-of-concept exploit exists for CVE-2026-85182, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-85182?

CVE-2026-85182 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2026-85182 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key