Back

MEDIUM

Frappe: Unrestricted API access to save_report

Published Jul 10, 2026

Description

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 10, 2026
Updated Jul 14, 2026
Reserved May 19, 2026
CISA Vulnrichment
Updated Jul 14, 2026
NVD
Status Deferred
Modified Jul 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 10, 2026
Updated Jul 14, 2026
Exploited since n/a
EUVD-2026-43099