Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it." | |
| Title | Frappe HR Permission Validation __init__.py get_attendance_requests authorization | |
| First Time appeared |
Frappe
Frappe hr |
|
| Weaknesses | CWE-285 CWE-863 |
|
| CPEs | cpe:2.3:a:frappe:hr:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe
Frappe hr |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-01T14:07:45.744Z
Reserved: 2026-09-27T10:58:22.433Z
Link: CVE-2026-101006
Updated: 2026-10-01T14:07:41.217Z
Status : Deferred
Published: 2026-09-28T07:17:20.023
Modified: 2026-10-01T15:17:20.313
Link: CVE-2026-101006
No data.
OpenCVE Enrichment
Updated: 2026-09-28T10:15:05Z