Junglewise Threat Intelligence

CVE-2026-39349: OrangeHRM inadequate encryption strength in sensitive fields

CVE-2026-39349 · Severity: low · CVSS 2.7 · Published 2026-04-07

Technologies: Orangehrm. Vendors: Orangehrm.

Executive brief

OrangeHRM is a human resource management system used to manage employee data and corporate HR processes. A security flaw in how the system encrypts sensitive information could allow an attacker with high-level administrative access to identify patterns in protected data. While this does not grant direct access to the full database, it could lead to the disclosure of sensitive employee information.

Technical details

OrangeHRM Open Source (versions 5.0 to 5.8) utilizes AES encryption in Electronic Codebook (ECB) mode to protect certain sensitive database fields. ECB mode is cryptographically insecure for multi-block data because it encrypts identical plaintext blocks into identical ciphertext blocks, preserving patterns that can be used to infer the underlying data. An attacker with high privileges (PR:H) and network access could exploit this inadequate encryption strength (CWE-326) to perform pattern disclosure attacks against stored data. The issue is resolved in version 5.8.1 by moving away from ECB mode.

Affected products

  • OrangeHRM OrangeHRM Open Source 5.0 to 5.8

Timeline

  • 2026-04-06: advisory: GitHub Security Advisory published
  • 2026-04-07: disclosed: CVE published to NVD
  • 2026-04-07: patched: Fix released in version 5.8.1

References

Related threats