Access Control Bypass Vulnerability in OrangeHRM Human Resource Management System
CVE-2026-39346

5.3MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39346?

OrangeHRM, a popular human resource management system, has a vulnerability that allows authenticated users to bypass access controls on modules disabled by administrators. This issue arises when users manipulate URL-encoded request paths, potentially gaining access to sensitive functionalities that should be restricted. The vulnerability affects versions 5.0 through 5.8 and has been resolved in version 5.8.1. For more information, refer to the advisory on GitHub.

Affected Version(s)

orangehrm >= 5.0, < 5.8.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.