File Resolution Vulnerability in OrangeHRM by OrangeHRM
CVE-2026-39345

4.6MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39345?

OrangeHRM Open Source, spanning versions 5.0 to 5.8, contains a security flaw where the application fails to properly restrict the resolution of email template files to its plugins directory. This vulnerability allows an authenticated user with the ability to modify the template path to access arbitrary local files on the server, potentially leading to unauthorized information disclosure. The issue has been addressed in version 5.8.1, which users are encouraged to upgrade to in order to safeguard their systems.

Affected Version(s)

orangehrm >= 5.0, < 5.8.1

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.