---
id: CVE-2026-101006
title: A flaw has been found in Frappe HR up to 16.15.0
summary: >-
  A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects
  the function get_expense_claims/get_shift_requests/get_attendance_requests of
  the file hrms/api/__init__.py of the component Permission Validation. This
  manipul…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-285
  - CWE-863
vendor: Frappe
product: HR
affected:
  - HR 16.0
  - HR 16.1
  - HR 16.2
  - HR 16.3
  - HR 16.4
  - HR 16.5
  - HR 16.6
  - HR 16.7
  - HR 16.8
  - HR 16.9
  - HR 16.10
  - HR 16.11
  - HR 16.12
  - HR 16.13
  - HR 16.14
  - HR 16.15.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T07:17:20.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101006'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-101006'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/919744'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410876'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410876/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T07:04:53.494Z'
---

## Overview

A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
