CVE-2026-108734
Received Received - Intake

Frappe CRM Missing Authorization in Document Linking

Vulnerability report for CVE-2026-108734, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
frappe crm 1.49.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in Frappe CRM versions 1.49.0 through 1.87.0. The API method get_linked_docs_of_document fails to enforce read permissions when retrieving linked records, allowing authenticated users to access sensitive data without proper checks. Attackers can exploit this to read call log phone numbers, deal organizations, and mention notification text from records they shouldn't access.

Detection Guidance

To detect this vulnerability, check if your Frappe CRM version is between 1.49.0 and 1.87.0. Review API calls to the get_linked_docs_of_document endpoint for unauthorized data access. Look for logs showing users retrieving call log phone numbers, deal organizations, or mention notifications without proper permissions.

Impact Analysis

If you use Frappe CRM versions 1.49.0 to 1.87.0, an attacker with valid credentials could access sensitive information such as phone numbers from call logs, organizations linked to deals, and message content from mentions. This could lead to data breaches, unauthorized access to confidential information, or compliance violations depending on the data exposed.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance failures, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Immediately upgrade Frappe CRM to a version beyond 1.87.0 where the vulnerability is patched. If upgrading is not possible, restrict access to the get_linked_docs_of_document API method and implement strict permission checks in the crm/api/doc.py file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108734. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart