Authentication Bypass Vulnerability in Frappe CRM by Frappe
CVE-2026-53761

8.2HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-53761?

Frappe CRM, an open-source customer relationship management tool, has a significant authentication bypass vulnerability that existed in versions before 1.73.0. This vulnerability arises through the use of logged invitation keys exposed in the crm/api, allowing unauthorized access to sensitive functionalities. Users are advised to upgrade to version 1.73.0 or later to mitigate this security risk. For more details, refer to the official advisory and release notes.

Affected Version(s)

crm < 1.73.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.