PT-2026-3914 · Horilla · Horilla

Whoisshuvam

·

Published

2026-01-22

·

Updated

2026-01-27

·

CVE-2026-24038

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Horilla version 1.4.0
Description Horilla, a Human Resource Management System (HRMS), contains a flaw in its two-factor authentication implementation. Specifically, the OTP handling logic has a flawed equality check. When an OTP expires, the server returns None. An attacker can bypass two-factor authentication by omitting the otp field from their POST request, causing the comparison user otp == otp to pass, even without a valid OTP. Targeting administrative accounts could lead to compromise of sensitive HR data and manipulation of employee records. The vulnerable parameter is otp.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-24038
GHSA-HQPV-FF5V-3HWF

Affected Products

Horilla