Unrestricted Doctype Access Vulnerability in Frappe Framework
CVE-2026-39351

6.9MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39351?

The Frappe Framework has a significant vulnerability that permits unrestricted access to Doctype definitions via its API. Versions prior to 16.14.0 and 15.104.0 are particularly affected, making it possible for unauthorized users to exploit this weakness. This could lead to exposure of sensitive data and potential manipulation of database entries. It is crucial for users of the framework to update to the latest versions to mitigate any risks associated with this vulnerability.

Affected Version(s)

frappe < 15.104.0 < 15.104.0

frappe >= 16.0.0-beta.1, < 16.14.0 < 16.0.0-beta.1, 16.14.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.