PT-2026-99771 · Frappe · Frappe Hr

·

CVE-2026-101006

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe HR versions prior to 16.15.0
Description An incorrect authorization issue exists within the Permission Validation component. The flaw allows remote exploitation by manipulating the employee argument in the get expense claims(), get shift requests(), and get attendance requests() functions located in the hrms/api/ init .py file.
Recommendations Update Frappe HR to version 16.15.0 or later. As a temporary mitigation, restrict access to the get expense claims(), get shift requests(), and get attendance requests() functions.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101006

Affected Products

Frappe Hr