Junglewise Threat Intelligence

CVE-2026-39351: Frappe unrestricted Doctype access via API exploit

CVE-2026-39351 · Severity: critical · CVSS 9.1 · Published 2026-04-07

Technologies: Frappe Technologies Frappe Framework, Frappe. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe is a web application framework used to build business software like ERPNext. A security flaw allows unauthorized users to access and manipulate internal data structures (Doctypes) through the application's programming interface (API). This could lead to the exposure of sensitive business information or unauthorized modification of records without proper credentials.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Frappe web framework's API. Prior to the patched versions, the framework failed to properly restrict access to 'Doctypes' (the core data schemas in Frappe) when accessed via specific API endpoints. A remote, unauthenticated attacker can exploit this to bypass intended access controls, allowing them to read or write data they should not have access to. The vulnerability is resolved in versions 15.104.0 and 16.14.0.

Affected products

  • Frappe Frappe < 15.104.0, >= 16.0.0-beta.1 < 16.14.0

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched

References

Related threats