PT-2026-60526 · Hireflow · Hireflow

CVE-2026-45336

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions HireFlow versions prior to 1.3
Description HireFlow is a web-based interview management system used for candidate management, interview scheduling, and hiring progress tracking. In the app.py file, the application assigns a hard-coded Flask secret key used to sign session cookies. An unauthenticated attacker with knowledge of this public source value can forge cookies containing the role=admin and user id variables to bypass authentication.
Recommendations Update to version 1.3.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45336
GHSA-X53G-JR84-JRV5

Affected Products

Hireflow