CVE-2026-39345 is a path traversal vulnerability affecting OrangeHRM Open Source versions 5.0 through 5.8 that permits authenticated users with the ability to influence template file paths to read arbitrary files from the affected system. The flaw stems from inadequate validation of email template file resolution, which fails to restrict access to the intended plugins directory. This vulnerability has been remediated in version 5.8.1. The vulnerability carries a CVSS v3.1 score of 4.9 (Medium severity) with a network-based attack vector that requires low complexity and high privilege credentials to exploit. While the confidentiality impact is rated as high, there is no integrity or availability impact associated with this issue. The attack does not require user interaction, making it executable by any authenticated administrator or privileged account capable of manipulating template paths. This vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the CISA Known Exploited Vulnerabilities catalog. The low EPSS score of 0.000520 indicates minimal likelihood of exploitation in real-world scenarios. Community attention remains limited, suggesting this issue has received modest attention relative to other disclosed vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.8.1CPE matchmatch criteria | cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.