CVE-2026-39347
Received Received - Intake
Improper Integrity Control in OrangeHRM Self-Appraisal Module

Publication date: 2026-04-07

Last updated on: 2026-04-09

Assigner: GitHub, Inc.

Description
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-07
Last Modified
2026-04-09
Generated
2026-05-09
AI Q&A
2026-04-07
EPSS Evaluated
2026-05-07
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
orangehrm orangehrm From 5.0 (inc) to 5.8.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability compromises the integrity of finalized appraisal records by allowing administrator users to modify self-appraisal submissions after they have been marked completed.

Loss of data integrity in HR records could potentially impact compliance with standards and regulations such as GDPR and HIPAA, which require accurate and tamper-proof record keeping.

However, the provided information does not explicitly state the direct effects on compliance with these regulations.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade OrangeHRM Open Source to version 5.8.1 or later, where the issue has been fixed.

Since the vulnerability requires administrator privileges to exploit, limiting administrator access and monitoring privileged user activities can also help reduce risk.


Can you explain this vulnerability to me?

CVE-2026-39347 is a vulnerability in OrangeHRM Open Source versions 5.0 to 5.8 that allows administrator users to modify their self-appraisal submissions even after those submissions have been marked as completed.

This breaks the integrity of finalized appraisal records because changes can be made to what should be immutable, finalized data.


How can this vulnerability impact me? :

The vulnerability impacts the integrity of appraisal records within the OrangeHRM system by allowing administrators to alter completed self-appraisals.

It requires high privileges to exploit but no user interaction, and can be exploited remotely with low attack complexity.

There is no impact on confidentiality or availability, and no further system impact beyond the integrity loss.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart