CVE-2026-108732
Received Received - Intake

Frappe HR Missing Authorization in Payroll Data Exposure

Vulnerability report for CVE-2026-108732, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authenticated users read payroll amounts. Attackers without HR roles can call the method over /api/method with enumerable Salary Slip or claim document names to disclose other employees' net pay and loan, advance, and claim balances.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
frappe hrms 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108732 is a missing authorization vulnerability in Frappe HR (hrms) versions before 16.11.0. The whitelisted get_account_and_amount method fails to restrict access properly. Authenticated users without HR roles can call this method via /api/method to read sensitive payroll data like net pay, loan balances, and claim amounts from Salary Slip or claim documents.

Detection Guidance

To detect this vulnerability, check if your Frappe HRMS version is below 16.11.0. Use the command: bench version to verify the installed version. If it is below 16.11.0, the system is vulnerable. Additionally, inspect API logs for unauthorized calls to /api/method with the get_account_and_amount method targeting Salary Slip or claim documents.

Impact Analysis

This vulnerability allows unauthorized users to access confidential payroll information of other employees. Attackers can retrieve net pay, loan balances, advance amounts, and claim balances without detection. This poses a significant privacy risk and could lead to misuse of sensitive financial data.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive personal and financial data. GDPR requires strict protection of personal data, while HIPAA mandates safeguards for protected health information. The breach of payroll data could result in non-compliance penalties and legal consequences.

Mitigation Strategies

Immediately upgrade Frappe HRMS to version 16.11.0 or later. If upgrading is not possible, restrict access to the /api/method endpoint and review API permissions to ensure only authorized users can call whitelisted methods. Monitor logs for suspicious activity targeting payroll-related documents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108732. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart