PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47194 frappe CVE debrief

Frappe is a full-stack web application framework. CVE-2026-47194 is a vulnerability in temporary magic login link generation, allowing remote attackers to cause emailed login links to point to an attacker-controlled domain and capture the login token. Organizations should be aware of this vulnerability and take steps to mitigate it by updating to versions 15.108.0 or 16.18.3. This issue has a CVSS score of 8.6 and is considered HIGH severity.

Vendor
frappe
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Organizations using Frappe, particularly those with security teams and vulnerability management processes, should be aware of this vulnerability and take steps to mitigate it. This includes updating to versions 15.108.0 or 16.18.3, reviewing and updating login link generation to prevent attacker-controlled Host headers, and monitoring for suspicious login link activity. Security teams should review the CVE record and assess their exposure to this vulnerability. Operators and administrators of Frappe-based systems should also be aware of the potential impact of this vulnerability on their systems and take steps to mitigate it. Vulnerability management teams should prioritize updating to versions 15.108.0 or 16.18.3 and review compensating controls for exposed systems while remediation is scheduled and verified. Platform administrators should review and update login link generation to prevent attacker-controlled Host headers and monitor for suspicious login link activity. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and prioritized for remediation. Rollback and change windows should be planned to minimize downtime and ensure that remediation is properly verified. Source tracking and monitoring should be implemented to detect and respond to potential exploitation attempts. Compensating controls, such as web application firewalls or intrusion detection systems, may be necessary to mitigate the vulnerability while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure that potential exploitation attempts are detected and responded to promptly. Asset inventory and configuration management processes should be reviewed to ensure that affected systems are properly identified and prioritized for remediation. Security teams should also review and update their incident response plans to ensure that they are prepared to respond to potential exploitation attempts. The vulnerability management team should track exceptions, retest remediated assets, and close the item only after evidence is documented. The security team should also review and update their risk

Technical summary

The CVE record indicates that temporary magic login link generation in Frappe can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3. The vulnerability has a CVSS score of 8.6 and is considered HIGH severity. Affected organizations should prioritize updating to versions 15.108.0 or 16.18.3 to mitigate the vulnerability.

Defensive priority

Organizations using Frappe should prioritize updating to versions 15.108.0 or 16.18.3 to mitigate the vulnerability.

Recommended defensive actions

  • Update Frappe to version 15.108.0 or 16.18.3
  • Review and update login link generation to prevent attacker-controlled Host headers
  • Monitor for suspicious login link activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record indicates that temporary magic login link generation in Frappe can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:07.913Z and has not been modified since then.