Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-45336: HireFlow: Attackers can access admin accounts
CVE-2026-45336
CVE-2026-45336
Summary
HireFlow's interview management system had a security issue that allowed attackers to gain access to admin accounts. This could have let unauthorized people control the system and make changes. HireFlow has since fixed the issue in version 1.3.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| stratonwebdesigners | hireflow | < 1.3 |
Original title
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key us...
Original description
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication. The advisory lists version 1.3 as fixed.
mitre CVSS3.1
10.0
Vulnerability type
CWE-798
Use of Hard-coded Credentials
- https://github.com/StratonWebDesigners/HireFlow/security/advisories/GHSA-x53g-jr... x_refsource_CONFIRM
- https://github.com/StratonWebDesigners/HireFlow/releases/tag/v1.3 x_refsource_MISC
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026