CVE-2026-47765
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Summary
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and 16.20.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| frappe | frappe | < 15.110.0 | affected |
| frappe | frappe | >= 16.0.0-beta.1, < 16.20.0 | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
References
- https://github.com/frappe/frappe/security/advisories/GHSA-cjjx-3v2x-37mf
- https://github.com/frappe/frappe/commit/caa95f64f96ccf62f9f9fdfc03274527105cb44e
- https://github.com/frappe/frappe/commit/d5c5499c95953b0bb28f7b4907add01663bb8ca0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.