github.com
https://github.com/frappe/hrms/releases/tag/v15.58.1 CVE-2026-40888
MEDIUM
Frappe HR vulnerable to Improper Access Control
Record summary
CVE-2026-40888 has a selected CVSS score of 6.5 (medium).
Description
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are available.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 21, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 15.58.1 | affected | |
| < 16.4.1 | affected |
References
3github.com
https://github.com/frappe/hrms/releases/tag/v16.4.1 github.comConfirmation
https://github.com/frappe/hrms/security/advisories/GHSA-4375-7rxj-9hfx