CVE-2026-24039: Horilla's Improper Access Control Allows Employees to Auto-Approve Documents
Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricted to administrator or high-privilege roles only; however, an insufficient server-side authorization check on the approval endpoint lets a standard employee modify the approval status of their own uploaded document. A successful exploitation allows users with only employee-level permissions to alter application state reserved for administrators. This undermines the integrity of HR processes (for example, acceptance of credentials, certifications, or supporting materials), and may enable submission of unvetted documents. This issue is fixed in version 1.5.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24039?
CVE-2026-24039 is classified as a high-severity vulnerability due to improper access control in Horilla that allows low-privileged employees to self-approve documents.
How do I fix CVE-2026-24039?
To fix CVE-2026-24039, upgrade to Horilla version 1.5.0 or later where this access control issue has been addressed.
Who is affected by CVE-2026-24039?
CVE-2026-24039 affects users of Horilla version 1.4.0, specifically those with low-privileged accounts who can approve documents.
What are the potential risks of CVE-2026-24039?
The risks of CVE-2026-24039 include unauthorized document approval, which can lead to fraudulent actions and data integrity issues.
What is the nature of the vulnerability described in CVE-2026-24039?
CVE-2026-24039 involves improper access control that allows low-privileged employees to auto-approve documents they upload in the Horilla HRMS.