Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108734
CVE-2026-108734
Description
Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.