CVE-2026-108733
Received Received - Intake

Authenticated Users Can Exploit Missing Authorization in Frappe HR Leave Allocation

Vulnerability report for CVE-2026-108733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted expire_allocation method that allows authenticated users to expire any leave allocation. Attackers without HR roles can name another employee's Leave Allocation in a POST request to zero its allocated leaves and wipe that employee's remaining leave balance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
frappe hrms 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108733 is a missing authorization vulnerability in Frappe HR (hrms) versions before 16.11.0. It affects the whitelisted expire_allocation method, allowing authenticated users without HR roles to exploit a POST request to expire any employee's leave allocation. This resets their remaining leave balance to zero by manipulating leave records without proper permission checks.

Detection Guidance

To detect this vulnerability, check if your Frappe HRMS version is below 16.11.0. Run the command: grep -r 'expire_allocation' /path/to/hrms/ to locate the method. Verify if the method lacks permission checks by examining the code for frappe.has_permission calls.

Impact Analysis

This vulnerability allows attackers to destroy an employee's leave balance by exploiting the expire_allocation method. This disrupts leave policy calculations, affects subsequent leave applications, and may lead to unauthorized modifications of sensitive HR data. Organizations using unpatched versions of Frappe HR are at risk of leave fraud or operational disruptions.

Compliance Impact

This vulnerability could impact compliance with data protection regulations like GDPR and HIPAA by enabling unauthorized modification of employee leave records. Unauthorized access to sensitive HR data may violate GDPR's principles of data integrity and confidentiality, especially if leave balances or related personal data are altered without proper authorization. For HIPAA, if the system handles protected health information, unauthorized changes to leave allocations could compromise compliance with access controls and audit requirements.

Mitigation Strategies

Immediately upgrade Frappe HRMS to version 16.11.0 or later. If upgrading is not possible, apply the patch from the commit 6ab7a50347367413b78ad5bd5d9e4b8c6653c81f to add permission checks to the expire_allocation method.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108733. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart