CVE-2026-40866Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employee’s document by changing the document ID in the upload request. This enables unauthorized modification of HR records.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Technical Details · 2026-04-21: 104-1604-2104-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40866 Insecure Direct Object Reference in Horilla HRMS 1.5.0 Employee Document Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40866

    Post summary

    The text announces the discovery of CVE‑2026‑40866, describing it as an insecure direct object reference in Horilla HRMS 1.5.0, but provides no further technical or exploit details.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40866 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allo… https://www.cve.org/CVERecord?id=CVE-2026-40866

    Post summary

    The text discloses an IDOR vulnerability in Horilla HRMS 1.5.0 (CVE-2026-40866), but does not mention any PoC, exploit code, active exploitation, or available patch/workaround.

    00000153
    57.2K followersView on X
  • Khokamoni@kh0kamoni
    Disclosure

    Pleased to share that 3 of my recent security findings in Horilla are now disclosed with CVEs: CVE-2026-40867 CVE-2026-40866 CVE-2026-40865 #CyberSecurity #SecurityResearch #WebSecurity #CVE #AppSec

    Post summary

    The author announces the public disclosure of three CVEs for Horilla, without providing additional technical or exploit details.

    0000046
    2 followersView on X

Explore more