Junglewise Threat Intelligence

CVE-2026-82634: Frappe Framework authorization bypass in Jinja template rendering

CVE-2026-82634 · Severity: medium · CVSS 6.5 · Published 2026-08-30

Vendors: Frappe.

Executive brief

Frappe Framework is a low-code web framework used to build enterprise business applications. A flaw in the template rendering endpoint allows users with basic print permissions to execute arbitrary database queries and read sensitive data like password hashes, bypassing normal access controls. This could lead to credential compromise and unauthorized data access across the entire application.

Technical details

The vulnerability is an authorization flaw in the render_jinja_template endpoint that fails to properly validate user permissions before rendering Jinja templates supplied as raw strings. Attackers with print permission on any document can exploit this to inject and execute arbitrary Jinja template code. The flaw allows execution of arbitrary SELECT statements against unrelated database tables, including the __Auth table containing password hashes. The endpoint is reachable over the network and requires only basic print permissions (a low privilege level). Patch availability and affected version ranges should be confirmed through the official Frappe advisory channels.

Affected products

  • Frappe Frappe Framework development builds

Timeline

  • 2026-08-30: disclosed

References