Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it." | |
| Title | Frappe HR Permission Validation __init__.py get_attendance_requests authorization | |
| First Time appeared |
Frappe
Frappe hr |
|
| Weaknesses | CWE-285 CWE-863 |
|
| CPEs | cpe:2.3:a:frappe:hr:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe
Frappe hr |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T06:15:12.353Z
Reserved: 2026-09-27T10:58:22.433Z
Link: CVE-2026-101006
No data.
Status : Received
Published: 2026-09-28T07:17:20.023
Modified: 2026-09-28T07:17:20.023
Link: CVE-2026-101006
No data.
OpenCVE Enrichment
Updated: 2026-09-28T07:30:17Z