๐Ÿ” CVE Alert

CVE-2026-108733

MEDIUM 4.3

Frappe HR (hrms) before 16.11.0 Missing Authorization via expire_allocation

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted expire_allocation method that allows authenticated users to expire any leave allocation. Attackers without HR roles can name another employee's Leave Allocation in a POST request to zero its allocated leaves and wipe that employee's remaining leave balance.

CWE CWE-862
Vendor frappe
Product hrms
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for frappe hrms

Be the first to know when new medium vulnerabilities affecting frappe hrms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

frappe / hrms
0 < 16.11.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/frappe-hrms-expire-allocation-missing-authorization-20261010 github.com: https://github.com/frappe/hrms/blob/0a54d2c7b8b6043e2705b6f557b6ed65260670dd/hrms/hr/doctype/leave_ledger_entry/leave_ledger_entry.py#L199-L228 github.com: https://github.com/frappe/hrms/commit/6ab7a50347367413b78ad5bd5d9e4b8c6653c81f github.com: https://github.com/frappe/hrms/releases/tag/v16.11.0 github.com: https://github.com/frappe/hrms vulncheck.com: https://www.vulncheck.com/advisories/frappe-hr-hrms-before-16.11.0-missing-authorization-via-expire-allocation

Credits

HaiND from the Post and Telecommunication Institute of Technology