OrangeHRM Open Source versions from 5.0 to 5.8 encrypt certain sensitive fields using AES in ECB mode. This mode of encryption preserves block-aligned plaintext patterns in ciphertext, potentially enabling pattern disclosure against stored data. The vulnerability has been addressed in version 5.8.1. To mitigate potential data exposure, organizations should assess their current deployment and update to the [truncated]
CVE-2026-39348 is a vulnerability in OrangeHRM Open Source from version 5.0 to 5.8. The vulnerability allows authenticated low-privilege users to read attachments via direct reference to attachment identifiers due to omitted authorization on job specification and vacancy attachment download handlers. This issue is fixed in version 5.8.1. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. [truncated]
CVE-2026-39346 is a vulnerability in OrangeHRM Open Source from version 5.0 to 5.8. Authenticated users could bypass disabled-module access controls via URL-encoded request paths. The issue is fixed in version 5.8.1. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Administrators and users of OrangeHRM Open Source versions 5.0 to 5.8 should apply the patch to prevent unauth [truncated]
OrangeHRM Open Source from version 5.0 to 5.8 fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vulnerability is classified as MEDIUM severity with a CVSS score of 4.6 and is fixed in version 5.8.1. System administrators and security teams should be aware of this vulner [truncated]