Junglewise Threat Intelligence

CVE-2026-44208: Frappe Framework IDOR in submit_discussion endpoint

CVE-2026-44208 · Severity: info · CVSS 6.9 · Published 2026-06-12

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe is a web application framework used to build business software. A security flaw in the discussion submission feature allows unauthorized users to access or modify resources they should not have permission to see. This could lead to unauthorized data access or manipulation within the application.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Frappe Framework's 'submit_discussion()' endpoint due to insufficient validation. An unauthenticated or low-privileged attacker can exploit this lack of authorization checks to access or manipulate resources. The vulnerability is categorized under CWE-284 (Improper Access Control) and CWE-285 (Improper Authorization). The issue is resolved in versions 15.107.0 and 16.17.0.

Affected products

  • Frappe Frappe Framework < 15.107.0, < 16.17.0

Timeline

  • 2026-06-03: advisory: GitHub Security Advisory GHSA-xh7m-j2j2-82f2 published
  • 2026-06-12: disclosed: CVE-2026-44208 published to NVD

References

Related threats