PT-2026-99135 · Horilla · Horilla

CVE-2026-63431

·

Published

2026-09-25

·

Updated

2026-09-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions 1.5.0-85 and earlier
Description An authentication bypass exists in the payroll module where the system fails to consistently authorize access before loading records. An authenticated employee can manipulate identifiers to access sensitive data belonging to other employees, including salary structures, allowance and deduction amounts, personal loan disbursements, and repayment schedules. This occurs within the payroll/views/component views.py file specifically in the allowances deductions tab, view single allowance(), and view single deduction() functions when processing the emp id, allowance id, or deduction id variables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63431
GHSA-C38J-FG3W-7RPH

Affected Products

Horilla