OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.
We have discovered 9 live websites that are affected by CVE-2026-39347.
| Product | |
| Category | Talent Management System |
| Vulnerable Domains | 9 live websites (100% of OrangeHRM install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 100% of all versions) |
| 3 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 4 websites |
| .net | 1 websites |
| .org | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.org | *,***,*** | ||
| ***.***.zm | *,***,*** | ||
| ***************.*************.com | **,***,*** | ||
| ****.*****.**.in | **,***,*** | ||
| ***.*******************.***.ng | **,***,*** | ||
| ***************.com | **,***,*** | ||
| *********.net | **,***,*** | ||
| *********.com | ***,***,*** | ||
| ************.com | ***,***,*** |
FAQ