Description

Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricted to administrator or high-privilege roles only; however, an insufficient server-side authorization check on the approval endpoint lets a standard employee modify the approval status of their own uploaded document. A successful exploitation allows users with only employee-level permissions to alter application state reserved for administrators. This undermines the integrity of HR processes (for example, acceptance of credentials, certifications, or supporting materials), and may enable submission of unvetted documents. This issue is fixed in version 1.5.0.

INFO

Published Date :

2026-01-22T03:43:41.476Z

Last Modified :

2026-01-22T12:30:11.282Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-24039 vulnerability.

Vendors Products
Horilla
  • Horilla
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-24039.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact