CVE-2026-39348 | OrangeHRM up to 5.8.0 Attachment authorization
A vulnerability described as problematic has been identified in OrangeHRM up to 5.8.0. This vulnerability affects unknown code of the component Attachment Handler. Executing a manipulation can lead to missing authorization.
The identification of this vulnerability is CVE-2026-39348. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.