VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026

Frappe: Auth. bypass via update_page

CVE-2026-49394

Description

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.