
CVE-2026-39348 OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attac… https://www.cve.org/CVERecord?id=CVE-2026-39348
Post summary
The message reports CVE‑2026‑39348 as an authorization bypass in OrangeHRM Open Source, affecting job specification and vacancy attachment handling.
