CVE-2026-47765: Frappe: Lack of Permissions in restore/bulk_restore
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulkrestore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and 16.20.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.110.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.20.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47765?
CVE-2026-47765 has a risk score of 44, indicating a moderate level of severity.
How do I fix CVE-2026-47765?
To mitigate CVE-2026-47765, upgrade to Frappe version 15.110.0 or 16.20.0 or later.
What impact does CVE-2026-47765 have on Frappe applications?
CVE-2026-47765 allows authenticated users to restore deleted documents without proper authorization.
Is CVE-2026-47765 applicable to older versions of Frappe?
Yes, CVE-2026-47765 affects all versions of Frappe prior to 15.110.0 and 16.20.0.
What are the affected endpoints in CVE-2026-47765?
The restore and bulk_restore endpoints are the ones affected by CVE-2026-47765.