CVE-2026-40889: Frappe HR has Improper Access Control on Files
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40889?
CVE-2026-40889 has been rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2026-40889?
To fix CVE-2026-40889, you should upgrade to Frappe HR versions 15.58.2 or 16.4.2, which contain the security patch.
Which versions of Frappe HR are affected by CVE-2026-40889?
CVE-2026-40889 affects Frappe HR versions prior to 15.58.2 and 16.4.2.
Can CVE-2026-40889 be exploited remotely?
Yes, CVE-2026-40889 can be exploited by authenticated users, allowing them to access unauthorized files.
What type of vulnerability is CVE-2026-40889?
CVE-2026-40889 is classified as an improper access control vulnerability.