CVE-2026-49394: Frappe: Auth. bypass via update_page
Published Jul 10, 2026
·Updated
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the updatepage endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.
Affected Software
1 affected component
frappe<16.19.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.19.0
Event History
Jul 10, 2026
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49394?
The severity of CVE-2026-49394 is high with a score of 7.1.
2
How do I fix CVE-2026-49394?
To fix CVE-2026-49394, upgrade Frappe to version 16.19.0 or later.
3
What does CVE-2026-49394 affect?
CVE-2026-49394 affects the Frappe framework, specifically through the update_page endpoint.
4
What type of vulnerability is CVE-2026-49394?
CVE-2026-49394 is an authorization bypass vulnerability.
5
When was CVE-2026-49394 published?
CVE-2026-49394 was published on July 10, 2026.