PT-2026-3912 · Horilla · Horilla

·

CVE-2026-24036

·

Published

2026-01-22

·

Updated

2026-01-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions 1.4.0 through 1.4.9
Description Horilla, a Human Resource Management System (HRMS), has an issue where unpublished job postings are exposed. This occurs through the ''/recruitment/recruitment-details//'' endpoint without requiring authentication. The response includes draft job titles, descriptions, and the application link, allowing unauthenticated users to view unpublished roles and access the application workflow. This unauthorized access can lead to the leakage of sensitive internal hiring information and candidate confusion.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24036
GHSA-Q4XR-W96P-3VG7

Affected Products

Horilla