Sceawere
Vulnerability Detail
CVE-2026-101006UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Frappe HR Authorization Bypass Flaw
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- Frappe
- Product
- HR
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-28T07:17:20.023Z",
"pubdate": "2026-09-28T07:17:20.023Z",
"executiveSummary": "A critical authorization bypass vulnerability has been identified in Frappe HR versions up to 16.15.0.\nThe flaw resides within the permission validation logic of the API endpoints responsible for retrieving expense claims, shift requests, and attendance records.\nThis vulnerability allows an unauthorized user to manipulate input parameters, specifically the 'employee' argument, to access sensitive data belonging to other employees.\nThe vulnerability is remotely exploitable, posing a significant risk to data confidentiality by circumventing mandatory access control checks.\nThe issue stems from insufficient server-side validation of the 'employee' parameter against the authenticated user's session context during request processing.\nThis allows an attacker to perform unauthorized data exfiltration of internal HR-related records without elevated privileges.\nThe vendor has acknowledged the vulnerability, noting that it has been previously reported and subsequently addressed through internal remediation efforts.",
"technicalDetails": "The vulnerability is located in the hrms/api/__init__.py file within the Frappe HR application. Specifically, the functions 'get_expense_claims', 'get_shift_requests', and 'get_attendance_requests' fail to implement robust authorization checks regarding the 'employee' argument provided in the API request.\nThe root cause is a failure in the permission validation layer where the application assumes the 'employee' identifier supplied by the client-side request is implicitly authorized for the requester. The system lacks a server-side verification mechanism to ensure that the requester has sufficient permission to view or query the records associated with the specified 'employee' ID.\nThe attack flow begins with an authenticated attacker sending a crafted HTTP request to any of the aforementioned API endpoints. By modifying the 'employee' parameter—a variable intended to scope the result set to a specific user—the attacker can bypass the intended access limitations. The backend logic proceeds to execute the database query using the attacker-supplied ID without verifying if the requesting user owns that ID or has the requisite administrative permissions to view it.\nThis manipulation results in Insecure Direct Object Reference (IDOR) behavior, allowing an attacker to iterate through employee identifiers to gain unauthorized read access to sensitive records such as expense claims, shift configurations, and attendance history. Because the validation logic fails to link the user's session token to the requested data scope, the application effectively leaks sensitive HR data.\nThe vulnerability affects Frappe HR versions up to 16.15.0 and is considered remotely exploitable, as these API endpoints are accessible via standard network interfaces. Exploitation does not require special administrative privileges, merely a valid user session. Upon successful exploitation, the impact includes unauthorized disclosure of personally identifiable information (PII) and internal business operational data.\nPost-exploitation, an attacker can harvest comprehensive lists of employee attendance, shift schedules, and financial expense documentation, which could be leveraged for reconnaissance or further social engineering attacks within the organization."
}