CVE-2026-45081 PUBLISHED

Frappe HR: Permission Bypass in HRMS Leave Details API

Assigner: GitHub_M
Reserved: 08.05.2026 Published: 27.05.2026 Updated: 27.05.2026

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor frappe
Product hrms
Versions
  • Version < 16.5.0 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE