Authorization Flaw in Horilla HR and CRM Software
CVE-2026-63431

6.5MEDIUM

Key Information:

Vendor

Horilla

Vendor
CVE Published:
25 September 2026

What is CVE-2026-63431?

Horilla HR and CRM software versions 1.5.0-85 and earlier exhibit a significant authorization inconsistency in the payroll module. Specifically, the system does not adequately enforce access controls in critical views such as allowances_deductions_tab, view_single_allowance, and view_single_deduction. This flaw allows authenticated users to manipulate request parameters to access sensitive information belonging to other employees, including salary details, allowance and deduction metrics, as well as personal loan information. Consequently, the privacy of employees is at risk, and the need for a patched version is urgent, as there is currently no comprehensive fix available.

Affected Version(s)

horilla-hr <= 1.5.0-85

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.