Junglewise Threat Intelligence

CVE-2026-47422: Frappe Framework missing authorization in reportview

CVE-2026-47422 · Severity: info · CVSS 5.3 · Published 2026-07-10

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe, Frappe Technologies.

Executive brief

Frappe is a web application framework used to build business software like ERPNext. A security flaw was found in the reportview component where certain data access points did not properly verify user permissions. This could allow an authenticated user to view or modify information they are not authorized to access, potentially compromising business data integrity.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Frappe Framework's reportview component. An endpoint within this component failed to implement appropriate permission checks, allowing users with low-level authentication (PR:L) to interact with the API in ways that should be restricted. An attacker could potentially read or modify data they do not have explicit permissions for. The issue is resolved in versions 15.107.5 and 16.18.2.

Affected products

  • Frappe Frappe Framework < 15.107.5, >= 16.0.0-beta.1 < 16.18.2

Timeline

  • 2026-06-17: advisory: GitHub Security Advisory published
  • 2026-07-10: disclosed: CVE published to NVD

References

Related threats