CVE-2026-40865: Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40865?
CVE-2026-40865 is classified as a medium severity vulnerability due to its potential impact on data confidentiality within Horilla HRMS.
Who is affected by CVE-2026-40865?
CVE-2026-40865 affects users of Horilla HRMS version 1.5.0, specifically authenticated users accessing employee document files.
How do I fix CVE-2026-40865?
To remediate CVE-2026-40865, update to a patched version of Horilla HRMS that addresses the insecure direct object reference issue.
What kind of vulnerability is CVE-2026-40865?
CVE-2026-40865 is classified as an insecure direct object reference (IDOR) vulnerability, allowing unauthorized access to sensitive documents.
What are the potential consequences of CVE-2026-40865?
The consequences of CVE-2026-40865 include unauthorized access to confidential employee documents, risking employee privacy and data security.