PatchSiren cyber security CVE debrief
CVE-2026-47194 frappe CVE debrief
Frappe is a full-stack web application framework. CVE-2026-47194 is a vulnerability in temporary magic login link generation, allowing remote attackers to cause emailed login links to point to an attacker-controlled domain and capture the login token. Organizations should be aware of this vulnerability and take steps to mitigate it by updating to versions 15.108.0 or 16.18.3. This issue has a CVSS score of 8.6 and is considered HIGH severity.
- Vendor
- frappe
- Product
- Unknown
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Organizations using Frappe, particularly those with security teams and vulnerability management processes, should be aware of this vulnerability and take steps to mitigate it. This includes updating to versions 15.108.0 or 16.18.3, reviewing and updating login link generation to prevent attacker-controlled Host headers, and monitoring for suspicious login link activity. Security teams should review the CVE record and assess their exposure to this vulnerability. Operators and administrators of Frappe-based systems should also be aware of the potential impact of this vulnerability on their systems and take steps to mitigate it. Vulnerability management teams should prioritize updating to versions 15.108.0 or 16.18.3 and review compensating controls for exposed systems while remediation is scheduled and verified. Platform administrators should review and update login link generation to prevent attacker-controlled Host headers and monitor for suspicious login link activity. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and prioritized for remediation. Rollback and change windows should be planned to minimize downtime and ensure that remediation is properly verified. Source tracking and monitoring should be implemented to detect and respond to potential exploitation attempts. Compensating controls, such as web application firewalls or intrusion detection systems, may be necessary to mitigate the vulnerability while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure that potential exploitation attempts are detected and responded to promptly. Asset inventory and configuration management processes should be reviewed to ensure that affected systems are properly identified and prioritized for remediation. Security teams should also review and update their incident response plans to ensure that they are prepared to respond to potential exploitation attempts. The vulnerability management team should track exceptions, retest remediated assets, and close the item only after evidence is documented. The security team should also review and update their risk
Technical summary
The CVE record indicates that temporary magic login link generation in Frappe can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3. The vulnerability has a CVSS score of 8.6 and is considered HIGH severity. Affected organizations should prioritize updating to versions 15.108.0 or 16.18.3 to mitigate the vulnerability.
Defensive priority
Organizations using Frappe should prioritize updating to versions 15.108.0 or 16.18.3 to mitigate the vulnerability.
Recommended defensive actions
- Update Frappe to version 15.108.0 or 16.18.3
- Review and update login link generation to prevent attacker-controlled Host headers
- Monitor for suspicious login link activity
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record indicates that temporary magic login link generation in Frappe can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3.
Official resources
-
CVE-2026-47194 CVE record
CVE.org
-
CVE-2026-47194 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:07.913Z and has not been modified since then.