Executive brief
OrangeHRM, a human resource management system, contains a flaw that allows administrator users to modify their own performance self-appraisals even after they have been officially completed and finalized. This undermines the integrity of the company's performance review records, as finalized documents should be immutable. While this does not lead to a data breach or system outage, it allows for the unauthorized alteration of official HR records.
Technical details
An improper authorization vulnerability (CWE-285) in OrangeHRM Open Source versions 5.0 through 5.8 allows users with administrative privileges to bypass state-change restrictions on performance reviews. Specifically, the application fails to properly enforce read-only status on self-appraisal submissions once they have reached a 'completed' state. An attacker with high privileges can exploit this over the network to alter finalized appraisal data, leading to a loss of data integrity. The issue is resolved in version 5.8.1 by implementing stricter server-side validation on the status of appraisal records during update requests.
Affected products
- OrangeHRM OrangeHRM Open Source 5.0 to 5.8
Timeline
- 2026-04-06: advisory: GitHub advisory published by vendor
- 2026-04-07: disclosed: CVE published to NVD
- 2026-04-07: patched: Fixed in version 5.8.1