Junglewise Threat Intelligence

CVE-2026-39346: OrangeHRM Open Source access control bypass in disabled modules

CVE-2026-39346 · Severity: medium · CVSS 5.4 · Published 2026-04-07

Technologies: Orangehrm. Vendors: Orangehrm.

Executive brief

OrangeHRM is a human resource management system used by businesses to manage employee data and administrative tasks. A security flaw in the Open Source version allowed logged-in users to access features and modules that administrators had intentionally disabled. This could lead to unauthorized access to sensitive HR functions or data that should be restricted.

Technical details

An improper access control vulnerability exists in OrangeHRM Open Source (versions 5.0 to 5.8) where the system fails to correctly validate requests for disabled modules when the request path is URL-encoded. An authenticated attacker with low privileges can bypass administrative restrictions by crafting specific URL-encoded requests to access the functionality of modules that have been explicitly disabled by an administrator. This allows for unauthorized interaction with restricted system components, potentially impacting the confidentiality and integrity of HR data. The issue is resolved in version 5.8.1.

Affected products

  • OrangeHRM OrangeHRM Open Source 5.0 to 5.8

Timeline

  • 2026-04-06: advisory: GitHub advisory published by maintainers
  • 2026-04-07: disclosed: NVD publication date
  • 2026-04-07: patched: Fix released in version 5.8.1

References

Related threats