Executive brief
OrangeHRM is a human resource management system used to manage employee data and corporate HR processes. A security flaw in how the system encrypts sensitive information could allow an attacker with high-level administrative access to identify patterns in protected data. While this does not grant direct access to the full database, it could lead to the disclosure of sensitive employee information.
Technical details
OrangeHRM Open Source (versions 5.0 to 5.8) utilizes AES encryption in Electronic Codebook (ECB) mode to protect certain sensitive database fields. ECB mode is cryptographically insecure for multi-block data because it encrypts identical plaintext blocks into identical ciphertext blocks, preserving patterns that can be used to infer the underlying data. An attacker with high privileges (PR:H) and network access could exploit this inadequate encryption strength (CWE-326) to perform pattern disclosure attacks against stored data. The issue is resolved in version 5.8.1 by moving away from ECB mode.
Affected products
- OrangeHRM OrangeHRM Open Source 5.0 to 5.8
Timeline
- 2026-04-06: advisory: GitHub Security Advisory published
- 2026-04-07: disclosed: CVE published to NVD
- 2026-04-07: patched: Fix released in version 5.8.1