CVE-2026-40888
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
21/04/2026
Last modified:
27/04/2026
Description
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are available.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:* | 15.58.1 (excluding) | |
| cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.4.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



