CVE-2026-40867

Source
https://cve.org/CVERecord?id=CVE-2026-40867
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40867.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40867
Aliases
  • GHSA-j6qp-j853-qrff
Published
2026-04-21T18:16:29.345Z
Modified
2026-08-12T03:51:28.622021857Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
Details

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files and internal documents across unrelated users or teams.

Database specific
{
    "cwe_ids": [
        "CWE-284",
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40867.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/horilla/horilla-hr

Affected ranges

Type
GIT
Repo
https://github.com/horilla/horilla-hr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "last_affected": "1.5.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40867.json"