CVE-2026-39345
MEDIUMOrangeHRM Affected by Arbitrary File Read via Path Traversal in Email Template Loader
Title source: cnaDescription
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vulnerability is fixed in 5.8.1.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/orangehrm/orangehrm/security/advisories/GHSA-xq24-qv66-9v3m
Scores
CVSS v3
4.9
EPSS
0.0032
EPSS Percentile
23.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
orangehrm/orangehrm
5.0 - 5.8.1
orangehrm/orangehrm
>= 5.0, < 5.8.1
Published
Apr 07, 2026
Tracked Since
Apr 08, 2026