Frappe HR Permission Validation __init__.py get_attendance_requests authorization
Published Sep 28, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Affected products
-
- Version 16.0StatusaffectedConstraints-
- Version 16.1StatusaffectedConstraints-
- Version 16.10StatusaffectedConstraints-
- Version 16.11StatusaffectedConstraints-
- Version 16.12StatusaffectedConstraints-
- Version 16.13StatusaffectedConstraints-
- Version 16.14StatusaffectedConstraints-
- Version 16.15.0StatusaffectedConstraints-
- Version 16.2StatusaffectedConstraints-
- Version 16.3StatusaffectedConstraints-
- Version 16.4StatusaffectedConstraints-
- Version 16.5StatusaffectedConstraints-
- Version 16.6StatusaffectedConstraints-
- Version 16.7StatusaffectedConstraints-
- Version 16.8StatusaffectedConstraints-
- Version 16.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (4)
- https://vuldb.com/cve/CVE-2026-101006 third-party-advisory
- https://vuldb.com/submit/919744 third-party-advisory
- https://vuldb.com/vuln/410876 vdb-entrytechnical-description
- https://vuldb.com/vuln/410876/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-101006 | third-party-advisory | |
| https://vuldb.com/submit/919744 | third-party-advisory | |
| https://vuldb.com/vuln/410876 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/410876/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.