Description
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with AES in ECB mode, which preserves block-aligned plaintext patterns in ciphertext and enables pattern disclosure against stored data. This vulnerability is fixed in 5.8.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with AES in ECB mode, which preserves block-aligned plaintext patterns in ciphertext and enables pattern disclosure against stored data. This vulnerability is fixed in 5.8.1. | |
| Title | OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T19:27:43.612Z
Reserved: 2026-04-06T20:28:38.394Z
Link: CVE-2026-39349
Updated: 2026-04-07T19:27:39.771Z
Status : Received
Published: 2026-04-07T19:16:46.067
Modified: 2026-04-07T19:16:46.067
Link: CVE-2026-39349
No data.
OpenCVE Enrichment
No data.
Weaknesses