Sceawere
Vulnerability Detail
CVE-2026-108732UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authorization in Frappe HR
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- frappe
- Product
- hrms
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authenticated users read payroll amounts. Attackers without HR roles can call the method over /api/method with enumerable Salary Slip or claim document names to disclose other employees' net pay and loan, advance, and claim balances.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:17.350Z",
"pubdate": "2026-10-11T13:17:17.350Z",
"executiveSummary": "Frappe HR (hrms) is affected by a critical missing authorization vulnerability residing within its whitelisted API framework. This flaw permits authenticated, non-privileged users to access sensitive financial data belonging to other personnel, bypassing mandatory role-based access control (RBAC) mechanisms.\nThe vulnerability specifically impacts versions prior to 16.11.0, including all releases within the 14.x series and versions up to 15.64.3 of the 15.x series. By interacting with the /api/method endpoint, an attacker can enumerate identifiers associated with Salary Slips, claims, or loan documents to exfiltrate payroll information, including net pay, loan balances, and advance payments.\nThe risk implication is significant, as it facilitates unauthorized disclosure of private employee financial records, violating internal privacy policies and regulatory compliance standards. Exploitation requires only a valid user account, as the underlying function fails to validate whether the requester possesses the HR-specific permissions required to access the requested data objects.\nThis vulnerability highlights a failure in server-side authorization enforcement for whitelisted methods, allowing arbitrary data access when object identifiers are predicted or brute-forced.",
"technicalDetails": "The root cause of this vulnerability is an improper access control check within the get_account_and_amount function, which is exposed via the Frappe framework's whitelist mechanism. In Frappe, whitelisting a method via the @frappe.whitelist() decorator makes the function accessible via the /api/method/[method_name] route. While the framework handles session-based authentication automatically, the application-level logic within the get_account_and_amount method fails to enforce authorization checks against the current user's security role.\nThe exploitation flow begins with an authenticated attacker interacting with the /api/method/hrms.payroll.doctype.salary_slip.salary_slip.get_account_and_amount endpoint (or relevant variant). The method accepts parameters such as the name (ID) of a Salary Slip, claim document, or loan document. Because the method does not verify if the requesting user is an HR administrator or the owner of the document, it executes the query against the underlying database regardless of the user's privilege level.\nThe attacker can enumerate document names—which often follow predictable patterns or sequential naming conventions—to cycle through internal records. By submitting requests with varied IDs, the attacker triggers the backend to retrieve and return the corresponding account details and monetary figures in a JSON response. This provides a direct channel for an attacker to perform mass data exfiltration of payroll amounts, loan balances, and other sensitive financial deductions associated with any employee in the system.\nThe vulnerability affects all Frappe HR (hrms) installations prior to 16.11.0, encompassing the entirety of the 14.x branch and versions 15.x up to 15.64.3. The attack is accessible over any network where the API is reachable, requiring only basic authentication. Once the attacker identifies valid document IDs through enumeration, the server provides the requested financial data without further verification, leading to full exposure of employee financial data. The lack of granular authorization logic ensures that once a user gains a valid session token, the breadth of the data exposure is limited only by the attacker's ability to iterate through document identifiers."
}