CVE-2026-40865
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.1EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
21 abr 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
horilla-opensource · horillaQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →