CVE-2026-49394

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-10 22:16

Updated : 2026-07-13 18:05


NVD link : CVE-2026-49394

Mitre link : CVE-2026-49394

CVE.ORG link : CVE-2026-49394


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization