---
id: CVE-2026-49394
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 16.19.0,
  authorization bypass was possible via the update_page endpoint in Workspace
  because public workspaces did not receive the required Workspace Manager edit
  check. This iss…
severity: none
cwe:
  - CWE-862
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49394'
references:
  - url: >-
      https://github.com/frappe/frappe/commit/2471d94c397dc23301b30ed3bb30353f53b33f2c
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/frappe/commit/6eba29d7ae80cdb4d0b2a245a477b1d2312736ca
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/39508'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/39526'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/releases/tag/v16.19.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-r24j-xrj8-273q'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0054
epssPercentile: 0.42935
ingestedAt: '2026-07-11T22:16:00.422Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
