PT-2026-30970 · Orangehrm · Orangehrm

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-39347

CVSS v4.0

5.1

Medium

AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-39347

Affected Products

Orangehrm