Description
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Invalid Permission Validation
Action: Apply Patch
AI Analysis

Impact

A flaw in Frappe HR allows an attacker to manipulate the employee argument passed to the get_attendance_requests function, causing the system to incorrectly grant access to attendance data. This results in unauthorized view or modification of sensitive employee records, and the vulnerability can be triggered from a remote location.

Affected Systems

The affected product is Frappe:HR version 16.15.0 and earlier. The failure occurs in the permission‑validation code within hrms/api/__init__.py for the get_expense_claims, get_shift_requests, and get_attendance_requests endpoints. No other versions are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 5.3 represents a moderate risk; the EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, involving crafted HTTP requests that supply a manipulated employee identifier. If exploited, an attacker can bypass authorization checks and access or alter attendance records for users they would not normally see.

Generated by OpenCVE AI on September 28, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Frappe HR (16.16 or later) where the permission validation bug has been fixed.
  • Ensure the application’s API endpoint for get_attendance_requests validates the employee parameter against the requester’s permissions before processing the request.
  • If a patch is not yet available, restrict access to the affected API endpoints to highly privileged users or disable them until a fix can be applied.

Generated by OpenCVE AI on September 28, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Title Frappe HR Permission Validation __init__.py get_attendance_requests authorization
First Time appeared Frappe
Frappe hr
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:frappe:hr:*:*:*:*:*:*:*:*
Vendors & Products Frappe
Frappe hr
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T06:15:12.353Z

Reserved: 2026-09-27T10:58:22.433Z

Link: CVE-2026-101006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:20.023

Modified: 2026-09-28T07:17:20.023

Link: CVE-2026-101006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses