Executive brief
OrangeHRM is a human resource management system used by organizations to manage employee data and recruitment. A security flaw in the Open Source version allows employees with low-level access to view and download sensitive documents, such as job specifications and vacancy attachments, that they are not authorized to see. This could lead to the exposure of internal hiring details or confidential job requirements.
Technical details
A missing authorization vulnerability (CWE-862) exists in the AbstractFileController subclasses of OrangeHRM Open Source. The application fails to validate if an authenticated user has the necessary permissions to access specific job specifications or vacancy attachments before serving the file. An attacker with low-privileged credentials can exploit this by providing direct attachment identifiers to the download handlers to retrieve files belonging to other users or departments. The issue is resolved in version 5.8.1 by implementing proper authorization checks in the affected controllers.
Affected products
- OrangeHRM OrangeHRM Open Source 5.0 to 5.8
Timeline
- 2026-04-06: advisory: GitHub Security Advisory published
- 2026-04-07: disclosed: NVD publication date
- 2026-04-07: patched: Fix released in version 5.8.1