๐Ÿ” CVE Alert

CVE-2026-101006

MEDIUM 4.3

Frappe HR Permission Validation __init__.py get_attendance_requests authorization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."

CWE CWE-863 CWE-285
Vendor frappe
Product hr
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for frappe hr

Be the first to know when new medium vulnerabilities affecting frappe hr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Frappe / HR
16.0 16.1 16.2 16.3 16.4 16.5 16.6 16.7 16.8 16.9 16.10 16.11 16.12 16.13 16.14 16.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/410876 vuldb.com: https://vuldb.com/vuln/410876/cti vuldb.com: https://vuldb.com/cve/CVE-2026-101006 vuldb.com: https://vuldb.com/submit/919744

Credits

๐Ÿ” zyx122126 (VulDB User) VulDB CNA Team