Access Control Bypass Vulnerability in OrangeHRM Human Resource Management System
CVE-2026-39346
5.3MEDIUM
What is CVE-2026-39346?
OrangeHRM, a popular human resource management system, has a vulnerability that allows authenticated users to bypass access controls on modules disabled by administrators. This issue arises when users manipulate URL-encoded request paths, potentially gaining access to sensitive functionalities that should be restricted. The vulnerability affects versions 5.0 through 5.8 and has been resolved in version 5.8.1. For more information, refer to the advisory on GitHub.
Affected Version(s)
orangehrm >= 5.0, < 5.8.1
