CVE-2026-39347

OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.


We have discovered 9 live websites that are affected by CVE-2026-39347.

Run a Free Instant Scan




Affected Software

Product  OrangeHRM
Category Talent Management System
Vulnerable Domains9 live websites (100% of OrangeHRM install base)
Vulnerable Versions
  • from 5 through 5.8.1
Vulnerable Versions Count2 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Apr 7, 2026
  • Updated - Apr 9, 2026

Website Distribution by Country

Number of websites using CVE-2026-39347
United States3 websites



Bangladesh1 websites
Germany1 websites
GB1 websites
India1 websites
Nigeria1 websites
Zambia1 websites

Website Distribution by TLD

Number of websites using CVE-2026-39347
.com4 websites
.net1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-39347

Top websites that are affected by CVE-2026-39347. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org GB*,***,***
***.***.zm Zambia*,***,***
***************.*************.com United States**,***,***
****.*****.**.in India**,***,***
***.*******************.***.ng Nigeria**,***,***
***************.com United States**,***,***
*********.net Germany**,***,***
*********.com Bangladesh***,***,***
************.com United States***,***,***
See full domain list

FAQ

CVE-2026-39347 is Improper Authorization in OrangeHRM
A total of 9 websites have been identified as vulnerable to CVE-2026-39347, based on global website indexing conducted by WebTechSurvey.
The OrangeHRM is affected by the CVE-2026-39347 vulnerability.
OrangeHRM versions up to 5.8.1 are vulnerable to CVE-2026-39347.
CVE-2026-39347 is resolved in version 5.8.1 of OrangeHRM.