{"id":"CVE-2026-101006","title":"A flaw has been found in Frappe HR up to 16.15.0","summary":"A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipul…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-285","CWE-863"],"vendor":"Frappe","product":"HR","affected":["HR 16.0","HR 16.1","HR 16.2","HR 16.3","HR 16.4","HR 16.5","HR 16.6","HR 16.7","HR 16.8","HR 16.9","HR 16.10","HR 16.11","HR 16.12","HR 16.13","HR 16.14","HR 16.15.0"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T07:17:20.023","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101006","references":[{"url":"https://vuldb.com/cve/CVE-2026-101006","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/919744","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410876","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410876/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T07:04:53.494Z","slug":"CVE-2026-101006","body":"## Overview\n\nA flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: \"This issue has already been reported by another individual, and based on that, we have fixed it.\"\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}