Security Advisory

CVE-2026-49394

N/A
UNKNOWN

Vulnerability Description

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.
Published Date July 10, 2026
Official Source NIST NVD Advisory