Workflow Approval Endpoint Vulnerability in Frappe
CVE-2026-63654

6.9MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-63654?

The Frappe Framework, specifically versions up to 16.31.0, contains a security vulnerability in the bulk_workflow_approval endpoint found in frappe/model/workflow.py. This endpoint inadequately restricts state-changing operations to POST requests, allowing the potential for an attacker to exploit the system by tricking an authenticated user into initiating approval actions with their own privileges. As a result, this could lead to unauthorized changes within workflow processes. Currently, there are no updates available to remediate this issue.

Affected Version(s)

frappe <= 16.31.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.