Unauthorized Access Vulnerability in Frappe HR
CVE-2026-40888

6.5MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40888?

An issue in Frappe HR, an open-source human resources management system, allows authenticated users with default roles to exploit specific API endpoints, accessing unauthorized information. This vulnerability affects versions prior to 15.58.1 and 16.4.1. To protect against potential exploitation, users should upgrade to the patched versions, as no workarounds are available.

Affected Version(s)

hrms < 15.58.1 < 15.58.1

hrms < 16.4.1 < 16.4.1

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.