CVE-2026-40865Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 104-1604-2104-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40865 Insecure Direct Object Reference in Horilla HRMS 1.5.0 Employee Document Viewer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40865

    Post summary

    A brief disclosure of an IDOR issue in Horilla HRMS 1.5.0, with no PoC, exploit, patch, or exploitation evidence presented.

    0000036
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40865 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any au… https://www.cve.org/CVERecord?id=CVE-2026-40865

    Post summary

    The note reports a newly disclosed CVE (CVE-2026-40865) describing an IDOR flaw in Horilla HRMS version 1.5.0, but it offers no PoC, exploitation details, patch information, or claims of false positive.

    00000130
    57.2K followersView on X
  • Khokamoni@kh0kamoni
    Disclosure

    Pleased to share that 3 of my recent security findings in Horilla are now disclosed with CVEs: CVE-2026-40867 CVE-2026-40866 CVE-2026-40865 #CyberSecurity #SecurityResearch #WebSecurity #CVE #AppSec

    Post summary

    The author announces three new CVE disclosures for Horilla, but provides no further technical details or evidence of exploitation.

    0000046
    2 followersView on X

Explore more