CVE-2026-94113: Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints

Published Sep 20, 2026
·
Updated

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call getprojectwisetimesheetdata, gettimesheetdetailrate, and gettimesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.

Affected Software

1 affected component
Frappe ERPNext<15.121.0, <16.34.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Frappe ERPNext to a version that resolves this vulnerability.

    Fixed in 15.121.0
  2. Upgrade

    Upgrade Frappe ERPNext to a version that resolves this vulnerability.

    Fixed in 16.34.0

Event History

Sep 20, 2026
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Frappe ERPNext versions before 15.121.0 are affected, as are 16.x versions before 16.34.0.

2

What access does an attacker need?

An attacker needs an authenticated ERPNext account with low privileges. No user interaction is required, and the vulnerable endpoints are reachable over the network.

3

What information could be exposed?

The affected timesheet endpoints can allow unauthorized enumeration and retrieval of billable time logs, including project names, billing amounts, and work descriptions.

4

Which endpoints should be investigated or restricted if updates cannot be applied immediately?

Prioritize the whitelisted get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints. Restrict access to authenticated users who have a legitimate need to view Timesheet data until affected instances are updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203