CVE Database
/

CVE-2026-39346

Back to search

CVE-2026-39346

Published: Apr 7, 2026

Modified: Apr 9, 2026

PUBLISHED

Description

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass disabled-module access controls via URL-encoded request paths and access functionality of modules disabled by an administrator. This vulnerability is fixed in 5.8.1.

VendorProductVersions

orangehrm

orangehrm

affected
>= 5.0, < 5.8.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now