Junglewise Threat Intelligence

CVE-2026-50026: Frappe Framework missing authorization in relink and set_email_password

CVE-2026-50026 · Severity: info · CVSS 6.9 · Published 2026-06-12

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe is a web application framework used to build business software. A security flaw in certain system components allowed unauthorized users to access or modify resources without the proper permissions. This could lead to unauthorized data access or changes to email settings. The issue has been fixed in the latest software updates.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Frappe Framework within the 'relink' and 'set_email_password' endpoints. Due to a lack of permission checks, a remote attacker can interact with these endpoints without proper authentication or authorization. This allows for unauthorized access to and modification of internal resources. The vulnerability is addressed in versions 15.107.0 and 16.17.0.

Affected products

  • Frappe Frappe Framework < 15.107.0, < 16.17.0

Timeline

  • 2026-06-03: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References

Related threats