CVE-2026-31878: Frappe: Possible SSRF by any authenticated user
Published Mar 11, 2026
·Updated
Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1, 15.100.0, and 16.6.0.
Affected Software
4 affected components
frappe<14.100.1, <15.100.0, <16.6.0
Frappe frappe<14.100.1
Frappe frappe>=15.0.0<15.100.0
Frappe frappe>=16.0.0<16.6.0
Event History
Mar 11, 2026
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 29, 58178
Event
via FIRST·01:13 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-31878?
CVE-2026-31878 is categorized as a high severity vulnerability due to its potential to allow SSRF attacks.
2
How do I fix CVE-2026-31878?
To fix CVE-2026-31878, upgrade to Frappe version 14.100.1, 15.100.0, or 16.6.0 or later.
3
Who is affected by CVE-2026-31878?
CVE-2026-31878 affects all versions of Frappe prior to 14.100.1, 15.100.0, and 16.6.0.
4
What type of attack does CVE-2026-31878 facilitate?
CVE-2026-31878 facilitates Server-Side Request Forgery (SSRF) attacks.
5
Can an unauthenticated user exploit CVE-2026-31878?
No, only authenticated users can exploit CVE-2026-31878 to perform SSRF attacks.