CVE-2026-39351
EUVD-2026-1986107.04.2026, 19:16
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | frappe | 𝑥 < 15.104.0 |
| frappe | frappe | 16.0.0 ≤ 𝑥 < 16.14.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration