Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-45336: HireFlow: Attackers can access admin accounts

CVE-2026-45336 CVE-2026-45336
Summary

HireFlow's interview management system had a security issue that allowed attackers to gain access to admin accounts. This could have let unauthorized people control the system and make changes. HireFlow has since fixed the issue in version 1.3.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
stratonwebdesigners hireflow < 1.3
Original title
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key us...
Original description
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication. The advisory lists version 1.3 as fixed.
mitre CVSS3.1 10.0
Vulnerability type
CWE-798 Use of Hard-coded Credentials
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026