PT-2026-57318 · Frappe · Frappe

CVE-2026-49394

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 16.19.0
Description An authorization bypass exists in the Workspace component. This occurs because public workspaces do not undergo the necessary Workspace Manager edit check when interacting with the 'update page' endpoint.
Recommendations Update to version 16.19.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49394
GHSA-R24J-XRJ8-273Q

Affected Products

Frappe