VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 14, 2026

Frappe: Unrestricted API access to save_report

CVE-2026-47422

Description

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.