๐Ÿ” CVE Alert

CVE-2026-108732

MEDIUM 4.3

Frappe HR (hrms) before 16.11.0 Missing Authorization via get_account_and_amount

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authenticated users read payroll amounts. Attackers without HR roles can call the method over /api/method with enumerable Salary Slip or claim document names to disclose other employees' net pay and loan, advance, and claim balances.

CWE CWE-862
Vendor frappe
Product hrms
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for frappe hrms

Be the first to know when new medium vulnerabilities affecting frappe hrms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

frappe / hrms
0 < 16.11.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/frappe-hrms-fnf-payroll-amount-oracle github.com: https://github.com/frappe/hrms/blob/0a54d2c7b8b6043e2705b6f557b6ed65260670dd/hrms/hr/doctype/full_and_final_statement/full_and_final_statement.py#L273-L327 github.com: https://github.com/frappe/hrms/commit/6ab7a50347367413b78ad5bd5d9e4b8c6653c81f github.com: https://github.com/frappe/hrms/releases/tag/v16.11.0 github.com: https://github.com/frappe/hrms vulncheck.com: https://www.vulncheck.com/advisories/frappe-hr-hrms-before-16.11.0-missing-authorization-via-get-account-and-amount

Credits

HaiND from the Post and Telecommunication Institute of Technology