CVE-2026-108734
Frappe CRM 1.49.0 through 1.87.0 Missing Authorization via get_linked_docs_of_document
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.
| CWE | CWE-862 |
| Vendor | frappe |
| Product | crm |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for frappe crm
Be the first to know when new medium vulnerabilities affecting frappe crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
frappe / crm
1.49.0 โค 1.87.0
References
hackmd.io: https://hackmd.io/@haind03/frappe-crm-linked-docs-unchecked-read-20261010 github.com: https://github.com/frappe/crm/blob/0d3910b456ef4fb913e77b29db011b3debc4f778/crm/api/doc.py#L684-L725 github.com: https://github.com/frappe/crm vulncheck.com: https://www.vulncheck.com/advisories/frappe-crm-1.49.0-through-1.87.0-missing-authorization-via-get-linked-docs-of-document
Credits
HaiND from the Post and Telecommunication Institute of Technology