Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41320

20
FAUCET Score

OVERVIEW CVE-2026-41320 is a SQL injection vulnerability affecting Frappe HR, an open-source human resources management system. The vulnerability exists in a specific endpoint that accepts specially crafted requests, potentially allowing attackers to extract sensitive information from the database. Versions 15.54.0 and 14.38.1 and later contain patches for this issue. SEVERITY This vulnerability carries a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and authenticated access. The threat actor must have valid credentials to exploit the vulnerability, but no user interaction is required. The primary impact is confidentiality loss, as attackers can extract information they would not normally access. Integrity and availability of the system are not affected. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00033 suggests minimal probability of exploitation within the next 30 days. The vulnerability has received limited community attention and carries a relatively low FAUCET Risk Score of 35/100, indicating this is not a priority threat. No workarounds are available, making prompt patching the recommended mitigation strategy.

Impacted Technologies

VendorProductVersion(s)CPE
< 14.38.1CPE matchmatch criteria
cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:*
>= 15.0.0, < 15.54.0CPE matchmatch criteria
cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 12th percentile among its peer group of 21,977 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / frappe/hrms/security/advisories/GHSA-745c-5q8r-vgj2
Vendor Advisory