CVE-2026-45081: Frappe HR: Permission Bypass in HRMS Leave Details API
Published May 27, 2026
·Updated
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.
Affected Software
1 affected component
Frappe Frappe HR<16.5.0
Event History
May 27, 2026
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45081?
CVE-2026-45081 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-45081?
To fix CVE-2026-45081, upgrade to Frappe HR version 16.5.0 or later.
3
What is affected by CVE-2026-45081?
CVE-2026-45081 affects the Frappe HRMS, allowing unauthorized access to leave details.
4
Who is vulnerable to CVE-2026-45081?
Authenticated employees of Frappe HR prior to version 16.5.0 are vulnerable to CVE-2026-45081.
5
What type of vulnerability is CVE-2026-45081?
CVE-2026-45081 is a permission bypass vulnerability in the HRMS Leave Details API.