CVE-2026-39348
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
07/04/2026
Last modified:
10/04/2026
Description
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attachment download handlers, allowing authenticated low-privilege users to read attachments via direct reference to attachment identifiers. This vulnerability is fixed in 5.8.1.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* | 5.0 (including) | 5.8.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



