CVE-2026-47185
MEDIUMFrappe Has Broken Access Control in its Workspace Save API
Title source: cnaDescription
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in version 16.18.0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/frappe/frappe/security/advisories/GHSA-mcr4-jc52-ww6x
X_Refsource_Misc x_refsource_misc
https://github.com/frappe/frappe/commit/8ef9e9076293c3f567b734ac9b1b81e63b805ab5
Scores
CVSS v4
5.1
EPSS
0.0039
EPSS Percentile
32.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
CWE-863
Status
published
Products (1)
frappe/frappe
< 16.18.0
Published
Aug 06, 2026
Tracked Since
Aug 07, 2026