Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it." | |
| Title | Frappe HR Permission Validation __init__.py get_attendance_requests authorization | |
| First Time appeared |
Frappe
Frappe hr |
|
| Weaknesses | CWE-285 CWE-863 |
|
| CPEs | cpe:2.3:a:frappe:hr:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe
Frappe hr |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T06:15:12.353Z
Reserved: 2026-09-27T10:58:22.433Z
Link: CVE-2026-101006
No data.
Status : Deferred
Published: 2026-09-28T07:17:20.023
Modified: 2026-09-28T15:16:04.793
Link: CVE-2026-101006
No data.
OpenCVE Enrichment
Updated: 2026-09-28T10:15:05Z
