CVE-2026-47422

MEDIUM

Frappe: Unrestricted API access to save_report

Title source: cna
STIX 2.1

Description

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

References (1)

Core 1
Core References

Scores

CVSS v4 5.3
EPSS 0.0028
EPSS Percentile 20.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
frappe/frappe < 15.107.5
frappe/frappe >= 16.0.0-beta.1, < 6.18.2
Published Jul 10, 2026
Tracked Since Jul 11, 2026