Authorization Flaw in Horilla HR and CRM Software
CVE-2026-63431
6.5MEDIUM
What is CVE-2026-63431?
Horilla HR and CRM software versions 1.5.0-85 and earlier exhibit a significant authorization inconsistency in the payroll module. Specifically, the system does not adequately enforce access controls in critical views such as allowances_deductions_tab, view_single_allowance, and view_single_deduction. This flaw allows authenticated users to manipulate request parameters to access sensitive information belonging to other employees, including salary details, allowance and deduction metrics, as well as personal loan information. Consequently, the privacy of employees is at risk, and the need for a patched version is urgent, as there is currently no comprehensive fix available.
Affected Version(s)
horilla-hr <= 1.5.0-85
