Junglewise Threat Intelligence

CVE-2026-47185: Frappe Workspace Save API broken access control

CVE-2026-47185 · Severity: info · CVSS 6.5 · Published 2026-08-06

Technologies: Frappe. Vendors: Frappe.

Executive brief

Frappe is a web application framework used to build business applications and internal tools. A flaw in the Workspace Save API allowed authenticated users to modify other users' private workspaces without authorization, potentially injecting malicious scripts that would execute when the workspace owner accesses it. This could lead to account compromise or data theft.

Technical details

The vulnerability is a broken access control flaw (CWE-284) in the Workspace Save API endpoint. The vulnerable component accepts a controlled workspace identifier from any authenticated user without verifying ownership or proper authorization checks. An attacker with valid authentication can craft a request targeting another user's private workspace to modify its contents and inject persistent scripts. The vulnerability was fixed in version 16.18.0 by adding authorization checks to verify that only the workspace owner (or a workspace manager for that specific user) can modify the workspace.

Affected products

  • Frappe Frappe before 16.18.0

Timeline

  • 2026-08-06: disclosed
  • 2026-08-06: patched: Fixed in version 16.18.0

References

Related threats