MEDIUM
Frappe: Unrestricted API access to save_report
Published Jul 10, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.38%
Description
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.
Affected products
-
- Version < 15.107.5StatusaffectedConstraints-
- Version >= 16.0.0-beta.1, < 6.18.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43099 Advisory
- https://github.com/frappe/frappe/security/advisories/GHSA-w8g7-j846-j248 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43099 | Advisory | |
| https://github.com/frappe/frappe/security/advisories/GHSA-w8g7-j846-j248 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 10, 2026
Updated Jul 14, 2026
Reserved May 19, 2026
Link CVE-2026-47422
CISA Vulnrichment
Updated Jul 14, 2026
ENISA EUVD
EUVD-2026-43099 Assigner GitHub_M
Published Jul 10, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-43099