PT-2026-95969 · Frappe · Erpnext

·

CVE-2026-94113

·

Published

2026-09-20

·

Updated

2026-09-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Frappe ERPNext versions prior to 15.121.0 Frappe ERPNext versions 16.x prior to 16.34.0
Description An information disclosure issue exists in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call the get projectwise timesheet data, get timesheet detail rate, and get timesheet endpoints to enumerate and retrieve billable time logs, including project names, billing amounts, and work descriptions, without proper authorization checks.
Recommendations Update to version 15.121.0 or later. Update to version 16.34.0 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94113
GHSA-9VPH-HQMM-G7HQ

Affected Products

Erpnext