CVE-2026-29081: Frappe: Possibility of SQL Injection due to improper fieldname sanitization
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issue has been patched in versions 14.100.1 and 15.100.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29081?
The severity of CVE-2026-29081 is considered high due to the potential for SQL injection.
How do I fix CVE-2026-29081?
To fix CVE-2026-29081, update Frappe to versions 14.100.1 or 15.100.0 or later.
Which versions of Frappe are affected by CVE-2026-29081?
Frappe versions prior to 14.100.1 and 15.100.0 are affected by CVE-2026-29081.
What types of attacks can exploit CVE-2026-29081?
CVE-2026-29081 can be exploited for SQL injection attacks, allowing unauthorized access to sensitive data.
Is CVE-2026-29081 specific to any configurations of Frappe?
No, CVE-2026-29081 affects all installations of Frappe prior to the fixed versions, regardless of configuration.