CVE-2026-45081: Frappe Hrms
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.
Affected products
- Frappe Hrms: before 16.5.0 (fixed in 16.5.0)
Published 2026-05-27. Last modified 2026-06-17.