CVE-2026-53761
Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0.
| CWE | CWE-287 |
| Vendor | frappe |
| Product | crm |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for frappe crm
Be the first to know when new unknown vulnerabilities affecting frappe crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
frappe / crm
< 1.73.0