CVE-2026-24036

Source
https://cve.org/CVERecord?id=CVE-2026-24036
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24036.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24036
Aliases
  • GHSA-q4xr-w96p-3vg7
Published
2026-01-22T03:21:32.538Z
Modified
2026-03-01T02:56:48.127359Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Horilla Exposes Unpublished Job Disclosures through Unauthenticated API
Details

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles, descriptions and application link allowing unauthenticated users to view unpublished roles and access the application workflow for unpublished jobs. Unauthorized access to unpublished job posts can leak sensitive internal hiring information and cause confusion among candidates. This issue has been fixed in version 1.5.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24036.json"
}
References

Affected packages

Git / github.com/horilla-opensource/horilla

Affected ranges

Type
GIT
Repo
https://github.com/horilla-opensource/horilla
Events

Affected versions

1.*
1.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24036.json"