CVE-2026-101006
Last modified
CVE-2026-101006 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation.
Description
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Frappe | HR | 16.0; 16.1; 16.2; 16.3; 16.4; 16.5; 16.6; 16.7; 16.8; 16.9; 16.10; 16.11; 16.12; 16.13; 16.14; 16.15.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-101006?
How severe is CVE-2026-101006?
How do I fix CVE-2026-101006?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-101000A vulnerability was determined in Netcore NBR100V2 1.3.24061…10
- CVE-2026-101001A vulnerability was identified in Netcore NBR200V2 1.3.24112…10
- CVE-2026-101002A security flaw has been discovered in Netcore NBR200V2 1.3.…9.9
- CVE-2026-101003A weakness has been identified in Cesanta Mongoose up to 7.2…5.3
- CVE-2026-101004A security vulnerability has been detected in notionnext-org…5.3
- CVE-2026-101005A vulnerability was detected in October CMS up to 4.3.4. Thi…7.3
- CVE-2026-101007A vulnerability has been found in aaPanel BaoTa up to 11.8.0…8.4
- CVE-2026-101008A vulnerability was found in aaPanel BaoTa up to 11.8.0. Imp…9.1
- CVE-2026-101009A vulnerability was determined in aaPanel BaoTa up to 11.8.0…8.4
- CVE-2026-10101ACM/MCE assisted-service writes raw referenced pull-secret c…6.3
- CVE-2026-101010A vulnerability was identified in aaPanel BaoTa up to 11.8.0…4.7
- CVE-2026-101011A security flaw has been discovered in aaPanel BaoTa up to 1…4.7
Are you affected by CVE-2026-101006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
