Executive brief
Frappe is a web application framework used to build business software. A security flaw allows logged-in users to view the private email configuration details of other users on the system. This could lead to the exposure of sensitive communication settings and potentially impact user privacy.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Frappe Framework due to insufficient authorization checks on email account objects. By manipulating identifiers in requests, an authenticated attacker can bypass intended access controls to retrieve email configuration details belonging to other users (CWE-639). The vulnerability is reachable over the network and requires authentication but no user interaction. The issue has been addressed in versions 15.107.0 and 16.17.0.
Affected products
- Frappe Frappe Framework < 15.107.0, < 16.17.0
Timeline
- 2026-06-01: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date