CVE-2026-101006: Frappe HR Permission Validation __init__.py get_attendance_requests authorization

Published Sep 28, 2026
·
Updated

A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function getexpenseclaims/getshiftrequests/getattendancerequests of the file hrms/api/init.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."

Affected Software

1 affected component
Frappe Frappe HR<=16.15.0

Event History

Sep 28, 2026
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
May 2, 58711
Event
via NVD·05:19 PM

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation is remote, but the CVSS vector indicates that the attacker needs low-level privileges. The affected authorization paths are get_expense_claims, get_shift_requests, and get_attendance_requests.

2

Which releases are known to be affected?

Frappe HR versions up to and including 16.15.0 are identified as affected. The available information states that the vendor has fixed the issue, but does not provide the first fixed version.

3

What is the practical impact of successful exploitation?

An attacker can manipulate the employee argument and bypass intended authorization checks, resulting in unauthorized disclosure of limited information. No integrity or availability impact is stated in the supplied severity vector.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203