CVE-2026-39349
Severity CVSS v4.0:
LOW
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
07/04/2026
Last modified:
10/04/2026
Description
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with AES in ECB mode, which preserves block-aligned plaintext patterns in ciphertext and enables pattern disclosure against stored data. This vulnerability is fixed in 5.8.1.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
2.70
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* | 5.0 (including) | 5.8.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



