CVE-2026-40888: Frappe HR vulnerable to Improper Access Control
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40888?
CVE-2026-40888 has been categorized as a medium severity vulnerability due to improper access control that allows authenticated users to access unauthorized information.
How do I fix CVE-2026-40888?
To fix CVE-2026-40888, upgrade Frappe HR to versions 15.58.1 or 16.4.1 or later, where the vulnerability has been addressed.
What is the impact of CVE-2026-40888 on Frappe HR?
CVE-2026-40888 allows authenticated users with default roles to exploit certain API endpoints to access sensitive information they should not have access to.
Which versions of Frappe HR are affected by CVE-2026-40888?
CVE-2026-40888 affects Frappe HR versions prior to 15.58.1 and 16.4.1.
Is it possible to exploit CVE-2026-40888 without authentication?
No, exploitation of CVE-2026-40888 requires an authenticated user with a default role.