Insufficient Validation in Frappe Cloud and ERPNext Authentication Process
CVE-2026-4894

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-4894?

A critical flaw in the Frappe Cloud and ERPNext authentication process allows attackers to bypass proper validation of email addresses. By manipulating the email field in the /api/method/press.api.account.signup endpoint, an unauthenticated remote attacker can submit multiple email addresses. The service incorrectly processes this input, treating it as a valid list of recipients and sending the One-Time Password (OTP) codes to all addresses provided. This exploitation can lead to unauthorized account registrations, impersonation during the registration process, and confirmation of registered email addresses without access to their respective mailboxes.

Affected Version(s)

Frappe Technologies Version before 23/03/2026

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel Jiménez Cámara
.