Arbitrary File Read Vulnerability in Frappe Web Application Framework
CVE-2026-39352

8.7HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-39352?

The Frappe Framework, a full-stack web application framework, is susceptible to an Arbitrary File Read vulnerability due to inadequate validation of file paths. This security flaw may allow unauthorized users to access sensitive files on the server, potentially leading to data exposure. To mitigate the risk, users are advised to upgrade to Frappe Framework versions 15.105.0, 16.15.0, or higher, where this vulnerability has been addressed.

Affected Version(s)

frappe < 15.105.0 < 15.105.0

frappe >= 15.106.0, < 16.15.0 < 15.106.0, 16.15.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.