CVE-2026-101006 Details
Description
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
An authorization flaw has been identified in Frappe HR versions prior to 16.15.0. The vulnerability resides in the Permission Validation component, specifically within the hrms/api/__init__.py file. It affects the get_expense_claims, get_shift_requests, and get_attendance_requests functions. The issue arises from improper handling of the employee argument, leading to incorrect authorization. This vulnerability can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-101006 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919744 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410876 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410876/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Frappe HR | <= 16.15.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion