Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles, descriptions and application link allowing unauthenticated users to view unpublished roles and access the application workflow for unpublished jobs. Unauthorized access to unpublished job posts can leak sensitive internal hiring information and cause confusion among candidates. This issue has been fixed in version 1.5.0.
References
Configurations
History
29 Jan 2026, 18:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:horilla:horilla:1.4.0:*:*:*:*:*:*:* | |
| First Time |
Horilla
Horilla horilla |
|
| References | () https://github.com/horilla-opensource/horilla/commit/9a585a1588431499092a49d7e82cb77daa4d99ee - Patch | |
| References | () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - Release Notes | |
| References | () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-q4xr-w96p-3vg7 - Exploit, Vendor Advisory |
22 Jan 2026, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-22 04:15
Updated : 2026-01-29 18:58
NVD link : CVE-2026-24036
Mitre link : CVE-2026-24036
CVE.ORG link : CVE-2026-24036
JSON object : View
Products Affected
horilla
- horilla
CWE
CWE-284
Improper Access Control
