CVE-2026-45081

MEDIUM

Frappe HR: Permission Bypass in HRMS Leave Details API

Title source: cna
STIX 2.1

Description

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
frappe/hrms < 16.5.0
Published May 27, 2026
Tracked Since May 27, 2026