PatchSiren

orangehrm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW orangehrm CVE published 2026-04-07

CVE-2026-39349

OrangeHRM Open Source versions from 5.0 to 5.8 encrypt certain sensitive fields using AES in ECB mode. This mode of encryption preserves block-aligned plaintext patterns in ciphertext, potentially enabling pattern disclosure against stored data. The vulnerability has been addressed in version 5.8.1. To mitigate potential data exposure, organizations should assess their current deployment and update to the [truncated]

MEDIUM orangehrm CVE published 2026-04-07

CVE-2026-39348

CVE-2026-39348 is a vulnerability in OrangeHRM Open Source from version 5.0 to 5.8. The vulnerability allows authenticated low-privilege users to read attachments via direct reference to attachment identifiers due to omitted authorization on job specification and vacancy attachment download handlers. This issue is fixed in version 5.8.1. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. [truncated]

MEDIUM orangehrm CVE published 2026-04-07

CVE-2026-39346

CVE-2026-39346 is a vulnerability in OrangeHRM Open Source from version 5.0 to 5.8. Authenticated users could bypass disabled-module access controls via URL-encoded request paths. The issue is fixed in version 5.8.1. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Administrators and users of OrangeHRM Open Source versions 5.0 to 5.8 should apply the patch to prevent unauth [truncated]

MEDIUM orangehrm CVE published 2026-04-07

CVE-2026-39345

OrangeHRM Open Source from version 5.0 to 5.8 fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vulnerability is classified as MEDIUM severity with a CVSS score of 4.6 and is fixed in version 5.8.1. System administrators and security teams should be aware of this vulner [truncated]