CVE-2026-49394 UNKNOWN

CVE-2026-49394

Published: 2026-07-10

Description

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…