Home

Description

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files and internal documents across unrelated users or teams.

PUBLISHED Reserved 2026-04-15 | Published 2026-04-21 | Updated 2026-04-21 | Assigner GitHub_M




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-284: Improper Access Control

CWE-639: Authorization Bypass Through User-Controlled Key

Product status

1.5.0
affected

References

github.com/...lla-hr/security/advisories/GHSA-j6qp-j853-qrff exploit

github.com/...lla-hr/security/advisories/GHSA-j6qp-j853-qrff

cve.org (CVE-2026-40867)

nvd.nist.gov (CVE-2026-40867)

Download JSON