CVE-2026-63431: Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR)

Published Sep 25, 2026
·
Updated

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/componentviews.py does not consistently authorize access in allowancesdeductionstab, viewsingleallowance, and viewsinglededuction before loading records selected by empid, allowanceid, or deductionid. An authenticated employee can substitute those identifiers to read another employee's salary structure, allowance and deduction amounts, personal loan disbursements, and repayment schedules without owning the record or holding payroll-view permissions. No complete fixed version is available as of this review.

Affected Software

1 affected component
Horilla horilla<=1.5.0-85

Event History

Sep 25, 2026
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Horilla employee account may be able to exploit it. The account does not need to own the targeted payroll record or have payroll-view permissions.

2

What does exploitation require?

An attacker needs a valid authenticated account and must modify employee, allowance, or deduction identifiers used by the affected views. No user interaction from the victim is required.

3

What information could be exposed?

Unauthorized users may read other employees' salary structures, allowance and deduction amounts, personal loan disbursements, and repayment schedules.

4

Are installations affected by default?

The affected component views do not consistently enforce authorization before loading records. Deployments running Horilla 1.5.0-85 or earlier should treat authenticated employee access to these views as potentially exposed.

5

What can be done if a complete fix is not available?

Restrict access to the affected payroll component views to only trusted users, and review authenticated access for attempts to request records using identifiers belonging to other employees. A complete fixed version was not available as of the review.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203