Missing Authorization in Frappe HR's Leave Allocation Method
CVE-2026-108733
5.3MEDIUM
What is CVE-2026-108733?
Frappe HR versions before 16.11.0 exhibit a significant security flaw in the expire_allocation method, which lacks proper authorization checks. This vulnerability permits authenticated users to manipulate other employees' leave allocations by sending crafted POST requests, enabling them to reduce the leave balance of any targeted individual, first potentially compromising organizational integrity and fairness in leave management.
Affected Version(s)
hrms 0 < 16.11.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
