CVE-2026-35614: Frappe has a SQL injection in bulk_update
Published Apr 7, 2026
·Updated
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulkupdate. This vulnerability is fixed in 16.14.0 and 15.104.0.
Affected Software
3 affected components
Frappe frappe<16.14.0, <15.104.0
Frappe frappe<15.104.0
Frappe frappe>=16.0.0<16.14.0
Event History
Apr 7, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35614?
CVE-2026-35614 has not been assigned a specific CVSS score but is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2026-35614?
To fix CVE-2026-35614, upgrade to Frappe version 16.14.0 or 15.104.0 or later.
3
Which versions of Frappe are affected by CVE-2026-35614?
CVE-2026-35614 affects Frappe versions prior to 16.14.0 and 15.104.0.
4
What type of vulnerability is CVE-2026-35614?
CVE-2026-35614 is a SQL injection vulnerability found in the bulk_update function of the Frappe framework.
5
Is there a patch available for CVE-2026-35614?
Yes, the patch for CVE-2026-35614 is included in Frappe versions 16.14.0 and 15.104.0.