---
id: CVE-2026-47422
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 15.107.5 and
  16.18.2, an endpoint in reportview lacked appropriate permission checks and
  that has since been fixed. This vulnerability is fixed in 15.107.5 and
  16.18.2.
severity: none
cwe:
  - CWE-862
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47422'
references:
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-w8g7-j846-j248'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00381
epssPercentile: 0.32034
ingestedAt: '2026-07-11T22:16:00.370Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
