VYPR
Medium severity4.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108732

CVE-2026-108732

Description

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authenticated users read payroll amounts. Attackers without HR roles can call the method over /api/method with enumerable Salary Slip or claim document names to disclose other employees' net pay and loan, advance, and claim balances.

Affected products

1
  • Frappe/Hrmsllm-fuzzy
    Range: <16.11.0, 14.x, 15.x through 15.64.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.