Vulnerability in Frappe Framework Allows Unauthorized Metadata Modification
CVE-2026-53569
5.3MEDIUM
What is CVE-2026-53569?
The Frappe Framework is vulnerable due to improper permission management in the toggle_like and mark_as_seen endpoints. Authenticated users can bypass read permissions, allowing them to alter the '_liked_by' metadata or change the visibility state of notes they should not have access to. This flaw exposes sensitive resource information and facilitates unauthorized modifications, posing significant security risks. As of now, there is no patched version available.
Affected Version(s)
frappe <= 16.31.0
