Insufficient Validation in Frappe Cloud and ERPNext Authentication Process
CVE-2026-4894
6.9MEDIUM
What is CVE-2026-4894?
A critical flaw in the Frappe Cloud and ERPNext authentication process allows attackers to bypass proper validation of email addresses. By manipulating the email field in the /api/method/press.api.account.signup endpoint, an unauthenticated remote attacker can submit multiple email addresses. The service incorrectly processes this input, treating it as a valid list of recipients and sending the One-Time Password (OTP) codes to all addresses provided. This exploitation can lead to unauthorized account registrations, impersonation during the registration process, and confirmation of registered email addresses without access to their respective mailboxes.
Affected Version(s)
Frappe Technologies Version before 23/03/2026
