OVERVIEW CVE-2026-41320 is a SQL injection vulnerability affecting Frappe HR, an open-source human resources management system. The vulnerability exists in a specific endpoint that accepts specially crafted requests, potentially allowing attackers to extract sensitive information from the database. Versions 15.54.0 and 14.38.1 and later contain patches for this issue. SEVERITY This vulnerability carries a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and authenticated access. The threat actor must have valid credentials to exploit the vulnerability, but no user interaction is required. The primary impact is confidentiality loss, as attackers can extract information they would not normally access. Integrity and availability of the system are not affected. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00033 suggests minimal probability of exploitation within the next 30 days. The vulnerability has received limited community attention and carries a relatively low FAUCET Risk Score of 35/100, indicating this is not a priority threat. No workarounds are available, making prompt patching the recommended mitigation strategy.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.38.1CPE matchmatch criteria | cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.54.0CPE matchmatch criteria | cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.