CVE-2026-86066
Horilla attendance approval endpoint is vulnerable to cross-site request forgery
Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.
| CWE | CWE-352 |
| Vendor | horilla |
| Product | horilla-hr |
| Published | Sep 25, 2026 |
Get instant alerts for horilla horilla-hr
Be the first to know when new unknown vulnerabilities affecting horilla horilla-hr are published โ delivered to Slack, Telegram or Discord.