CVE 5.3 MEDIUM

Frappe: Broken Access Control on Private Files_CVE-2026-47182

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.

Basic Information

ID CVE-2026-47182
Source GitHub_M
Published Jun 12, 2026 at 14:39

Affected Product

Vendor frappe
Product frappe
Version < 16.17.4
Affected Versions frappe frappe < 16.17.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.