Vulnerability in Frappe Framework Allows Unauthorized Metadata Modification
CVE-2026-53569

5.3MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-53569?

The Frappe Framework is vulnerable due to improper permission management in the toggle_like and mark_as_seen endpoints. Authenticated users can bypass read permissions, allowing them to alter the '_liked_by' metadata or change the visibility state of notes they should not have access to. This flaw exposes sensitive resource information and facilitates unauthorized modifications, posing significant security risks. As of now, there is no patched version available.

Affected Version(s)

frappe <= 16.31.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.