CVE-2026-49394
frappe
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.
- CVSS
- 7.1
- EPSS
- 0.31% 23.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11