CVE-2026-47765
Received Received - Intake

Frappe Framework Document Permission Bypass via Restore Endpoints

Vulnerability report for CVE-2026-47765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: GitHub, Inc.

Description

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and 16.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
frappe frappe to 15.110.0 (exc)
frappe frappe to 16.20.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Frappe is a web application framework. Versions before 15.110.0 and 16.20.0 have a flaw in the restore and bulk_restore endpoints. These endpoints do not enforce proper document permission checks, allowing authenticated users to restore deleted documents without authorization.

Impact Analysis

An attacker with authenticated access could restore deleted documents they should not have permission to access. This could lead to unauthorized data exposure, data corruption, or bypassing intended access controls.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR's data integrity principles or HIPAA's access control rules. Unauthorized document restoration may lead to data breaches or unauthorized access.

Mitigation Strategies

Update Frappe to version 15.110.0 or later if using version 15.x, or to version 16.20.0 or later if using version 16.x. This addresses the unauthorized document restoration issue by applying proper permission checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart