Junglewise Threat Intelligence

CVE-2026-47765: Frappe authorization bypass in document restore endpoints

CVE-2026-47765 · Severity: info · Published 2026-08-06

Technologies: Frappe. Vendors: Frappe.

Executive brief

Frappe is a full-stack web application framework used to build enterprise business applications. A flaw in the document restore functionality allows authenticated users to restore deleted documents without proper permission checks, potentially exposing sensitive business data that should not be accessible to those users.

Technical details

The vulnerability exists in the restore and bulk_restore endpoints of Frappe, which fail to enforce appropriate document permission checks before allowing users to restore deleted documents. An authenticated attacker can restore any deleted document regardless of their authorization level for that document. The root cause is insufficient permission validation in the deleted_document doctype's restore functionality. The fix, applied in versions 15.110.0 and 16.20.0, adds proper metadata retention and permission checks to ensure only authorized users can restore documents.

Affected products

  • Frappe Frappe Before 15.110.0 and before 16.20.0

Timeline

  • 2026-08-06: disclosed
  • 2026-08-06: patched: Fixed in versions 15.110.0 and 16.20.0

References

Related threats