Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39345

20
FAUCET Score

CVE-2026-39345 is a path traversal vulnerability affecting OrangeHRM Open Source versions 5.0 through 5.8 that permits authenticated users with the ability to influence template file paths to read arbitrary files from the affected system. The flaw stems from inadequate validation of email template file resolution, which fails to restrict access to the intended plugins directory. This vulnerability has been remediated in version 5.8.1. The vulnerability carries a CVSS v3.1 score of 4.9 (Medium severity) with a network-based attack vector that requires low complexity and high privilege credentials to exploit. While the confidentiality impact is rated as high, there is no integrity or availability impact associated with this issue. The attack does not require user interaction, making it executable by any authenticated administrator or privileged account capable of manipulating template paths. This vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the CISA Known Exploited Vulnerabilities catalog. The low EPSS score of 0.000520 indicates minimal likelihood of exploitation in real-world scenarios. Community attention remains limited, suggesting this issue has received modest attention relative to other disclosed vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, < 5.8.1CPE matchmatch criteria
cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.6MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 17th percentile among its peer group of 3,566 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / orangehrm/orangehrm/security/advisories/GHSA-xq24-qv66-9v3m
Vendor Advisory