CVE-2026-40867Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files and internal documents across unrelated users or teams.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 104-1604-2104-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40867 Broken Access Control in Horilla HRMS 1.5.0 Helpdesk Attachment Viewer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40867

    Post summary

    The text identifies a new CVE for a broken access control flaw in Horilla HRMS and provides a link to a vulnerability database entry.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40867 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows an… https://www.cve.org/CVERecord?id=CVE-2026-40867

    Post summary

    The post reveals a broken access control flaw in Horilla HRMS 1.5.0 affecting the helpdesk attachment viewer.

    00000126
    57.2K followersView on X
  • Khokamoni@kh0kamoni
    Disclosure

    Pleased to share that 3 of my recent security findings in Horilla are now disclosed with CVEs: CVE-2026-40867 CVE-2026-40866 CVE-2026-40865 #CyberSecurity #SecurityResearch #WebSecurity #CVE #AppSec

    Post summary

    The user announced the disclosure of three new CVEs in Horilla but provided no further technical or exploit information.

    0000046
    2 followersView on X

Explore more