CVE-2026-40867: Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files and internal documents across unrelated users or teams.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40867?
CVE-2026-40867 is considered a high severity vulnerability due to its potential to expose sensitive attachments to unauthorized users.
How do I fix CVE-2026-40867?
To fix CVE-2026-40867, upgrade to a patched version of Horilla beyond 1.5.0, where access controls for helpdesk attachments are properly implemented.
What is CVE-2026-40867?
CVE-2026-40867 is a vulnerability in Horilla 1.5.0 that allows authenticated users to manipulate attachment IDs and gain unauthorized access to helpdesk attachments.
Who is affected by CVE-2026-40867?
Any user utilizing Horilla version 1.5.0 with the helpdesk feature is potentially affected by CVE-2026-40867.
Can CVE-2026-40867 be exploited remotely?
Yes, CVE-2026-40867 can be exploited remotely by any authenticated user with access to the helpdesk attachment viewer.