{"id":"CVE-2026-101006","published":"2026-09-28T07:17:20.023","lastModified":"2026-09-28T15:16:04.793","description":"A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: \"This issue has already been reported by another individual, and based on that, we have fixed it.\"","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-285","CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-101006","tags":[]},{"url":"https://vuldb.com/submit/919744","tags":[]},{"url":"https://vuldb.com/vuln/410876","tags":[]},{"url":"https://vuldb.com/vuln/410876/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}