Executive brief
OrangeHRM, a popular human resource management platform, contains a security flaw in its email template system. An authorized user with high-level privileges can exploit this to access sensitive files stored on the server that they should not be able to see. This could lead to the exposure of configuration files or other internal system data, potentially compromising the security of the entire HR platform.
Technical details
A path traversal vulnerability (CWE-22) exists in OrangeHRM Open Source versions 5.0 through 5.8. The application fails to properly validate or restrict email template file resolution to the designated plugins directory. An authenticated attacker with high privileges (PR:H) who can influence the template path can use traversal sequences to read arbitrary local files on the underlying server. The vulnerability is exploited over the network without user interaction. The issue is resolved in version 5.8.1.
Affected products
- OrangeHRM OrangeHRM Open Source 5.0 to 5.8
Timeline
- 2026-04-06: advisory: Vendor advisory published on GitHub
- 2026-04-07: disclosed: CVE published to NVD
- 2026-04-07: patched: Fix released in version 5.8.1