CVE-2026-86066: CWE-352: Cross-Site Request Forgery (CSRF) in horilla horilla-hr
Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.
AI Analysis
Technical Summary
Horilla-hr, an HR and CRM software, has a CSRF vulnerability (CWE-352) in the approve_validate_attendance_request endpoint (/attendance/approve-validate-attendance-request/) prior to version 2.0.0. The endpoint changes attendance validation state via an HTTP GET request without CSRF protection, allowing an unauthenticated attacker to induce a logged-in manager with the appropriate permission (attendance.change_attendance) to perform unauthorized attendance approvals. The attack leverages the victim's SameSite=Lax session cookie, causing the approval to be recorded under the victim's identity in the audit trail. This vulnerability is resolved in version 2.0.0.
Potential Impact
An attacker can cause a logged-in manager to unknowingly approve attendance requests, potentially leading to unauthorized modifications in attendance records. The approvals are attributed to the victim in audit logs, which could affect accountability and trust in the system. The vulnerability requires the victim to be logged in and have the attendance.change_attendance permission. There are no known exploits in the wild as of the publication date.
Mitigation Recommendations
Upgrade horilla-hr to version 2.0.0 or later, where this CSRF vulnerability is fixed. Since the vendor advisory confirms the issue is resolved in 2.0.0, applying this official fix is the recommended remediation. No other mitigation steps are indicated.
CVE-2026-86066: CWE-352: Cross-Site Request Forgery (CSRF) in horilla horilla-hr
Description
Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.
CVSS v4.0
Score 5.9medium
Affected software
horilla
horilla-hr
pkg:github/horilla/horilla-hrRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Horilla-hr, an HR and CRM software, has a CSRF vulnerability (CWE-352) in the approve_validate_attendance_request endpoint (/attendance/approve-validate-attendance-request/) prior to version 2.0.0. The endpoint changes attendance validation state via an HTTP GET request without CSRF protection, allowing an unauthenticated attacker to induce a logged-in manager with the appropriate permission (attendance.change_attendance) to perform unauthorized attendance approvals. The attack leverages the victim's SameSite=Lax session cookie, causing the approval to be recorded under the victim's identity in the audit trail. This vulnerability is resolved in version 2.0.0.
Potential Impact
An attacker can cause a logged-in manager to unknowingly approve attendance requests, potentially leading to unauthorized modifications in attendance records. The approvals are attributed to the victim in audit logs, which could affect accountability and trust in the system. The vulnerability requires the victim to be logged in and have the attendance.change_attendance permission. There are no known exploits in the wild as of the publication date.
Mitigation Recommendations
Upgrade horilla-hr to version 2.0.0 or later, where this CSRF vulnerability is fixed. Since the vendor advisory confirms the issue is resolved in 2.0.0, applying this official fix is the recommended remediation. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-04T19:34:03.099Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab6f6acf7a7c541065ec4dc
Added to database: 09/25/2026, 22:33:16 UTC
Last enriched: 09/25/2026, 22:48:04 UTC
Last updated: 09/26/2026, 02:46:30 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.