SQL Injection Vulnerability in Frappe Framework by Frappe Technologies
CVE-2026-35614

9.3CRITICAL

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35614?

Frappe Framework, a popular web application framework, contains a SQL injection flaw within its bulk_update functionality for versions prior to 16.14.0 and 15.104.0. This vulnerability could allow an attacker to manipulate SQL queries, leading to unauthorized data access and potential data corruption. Users are advised to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

frappe < 15.104.0 < 15.104.0

frappe >= 16.0.0-beta.1, < 16.14.0 < 16.0.0-beta.1, 16.14.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.