CVE-2026-45081: Frappe Hrms

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.

Affected products

  • Frappe Hrms: before 16.5.0 (fixed in 16.5.0)

Published 2026-05-27. Last modified 2026-06-17.