๐Ÿ” CVE Alert

CVE-2026-47185

UNKNOWN 0.0

Frappe Has Broken Access Control in its Workspace Save API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in version 16.18.0.

CWE CWE-863 CWE-79
Vendor frappe
Product frappe
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frappe / frappe
< 16.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/frappe/security/advisories/GHSA-mcr4-jc52-ww6x github.com: https://github.com/frappe/frappe/commit/8ef9e9076293c3f567b734ac9b1b81e63b805ab5