Integrity Issues in OrangeHRM Open Source HRM System
CVE-2026-39347

5.1MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39347?

The OrangeHRM Open Source HRM system has a vulnerability that allows administrator users to modify self-appraisal submissions even after they have been finalized. This fact undermines the integrity of completed appraisal records, which can lead to unauthorized changes and misrepresentation of user evaluations. The issue has been resolved in version 5.8.1.

Affected Version(s)

orangehrm >= 5.0, < 5.8.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.