CVE-2026-45336
HireFlow versions 1.2 and earlier contain a hard‑coded Flask secret_key used to sign session cookies. An attacker who knows this value can forge cookies that appear to be from an administrator, allowing them to bypass authentication. The vulnerability is resolved in version 1.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of HireFlow version 1.2 or earlier.
Real-world impact
Unauthenticated attackers can gain administrative access to the interview management system, potentially viewing, modifying, or deleting candidate data and hiring records.
Why this severity
CVSS base score 10 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction, with high confidentiality and integrity impacts.
What to do about it
- 01Upgrade HireFlow to version 1.3 or later.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.