EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to correlated intelligence
Vulnerability

CVE-2026-86066

Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.

Sharing
PUBLIC-OSINT
Confidence
100
Source
The CVE Program
Updated
26/09/2026 04:09

Description

Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.

STIX identifiervulnerability--07780e0d-0fb8-59cd-a6b0-482744ef3822
First observation-
Last observation-
Known relationships7

Aliases and classifications

CWE-352Cross-Site Request Forgery (CSRF)

Minimised technical details

No raw data
cisa kev
False
EudorIA correlation

Intel catalogue

The vulnerability is also available in the EudorIA editorial catalogue.

Open EudorIA analysis

Presence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.