๐Ÿ” CVE Alert

CVE-2026-39346

MEDIUM 6.5

OrangeHRM has Improper Access Control Allowing Access to Disabled Modules via URL Encoding

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
12th

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass disabled-module access controls via URL-encoded request paths and access functionality of modules disabled by an administrator. This vulnerability is fixed in 5.8.1.

CWE CWE-284
Vendor orangehrm
Product orangehrm
Published Apr 7, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for orangehrm orangehrm

Be the first to know when new medium vulnerabilities affecting orangehrm orangehrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

orangehrm / orangehrm
>= 5.0, < 5.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/orangehrm/orangehrm/security/advisories/GHSA-f254-w9w8-xc8q