CVE-2026-101006: Frappe HR Permission Validation __init__.py get_attendance_requests authorization
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function getexpenseclaims/getshiftrequests/getattendancerequests of the file hrms/api/init.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation is remote, but the CVSS vector indicates that the attacker needs low-level privileges. The affected authorization paths are get_expense_claims, get_shift_requests, and get_attendance_requests.
Which releases are known to be affected?
Frappe HR versions up to and including 16.15.0 are identified as affected. The available information states that the vendor has fixed the issue, but does not provide the first fixed version.
What is the practical impact of successful exploitation?
An attacker can manipulate the employee argument and bypass intended authorization checks, resulting in unauthorized disclosure of limited information. No integrity or availability impact is stated in the supplied severity vector.