CVE-2026-47765

HIGH

Frappe: Lack of Permissions in restore/bulk_restore

Title source: cna
STIX 2.1

Description

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and 16.20.0.

Scores

CVSS v4 7.1
EPSS 0.0043
EPSS Percentile 35.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
frappe/frappe < 15.110.0
frappe/frappe >= 16.0.0-beta.1, < 16.20.0
Published Aug 06, 2026
Tracked Since Aug 07, 2026