NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-40865
Summary

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records.

Publication Date April 22, 2026, 4:16 a.m.
Registration Date April 25, 2026, 4:03 a.m.
Last Update April 23, 2026, 6:05 a.m.
Related information, measures and tools
Common Vulnerabilities List