PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47765 frappe CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:08.960Z and has not been modified since then. Frappe versions 15.110.0 and 16.20.0 or later address the issue. Organizations using Frappe should prioritize patching to prevent potential data exposure and review compensating controls for exposed systems. The vulnerability affects the restore and bulk_restore endpoints, allowing authenticated users to restore deleted documents without required authorization. This issue is fixed in Frappe versions 15.110.0 and 16.20.0. Organizations should verify their deployments, review configurations, and monitor for suspicious activity related to document restoration.

Vendor
frappe
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Organizations using Frappe, especially those with multiple users or sensitive data, should be aware of this vulnerability and take steps to patch their systems. Affected operators, platforms, and security teams should review configurations, monitor for suspicious activity, and plan vendor-supported updates or mitigations.

Technical summary

The restore and bulk_restore endpoints in Frappe do not apply appropriate document permission checks. This allows an authenticated user to restore deleted documents without the required authorization. The issue is fixed in Frappe versions 15.110.0 and 16.20.0. Organizations using Frappe should prioritize patching to prevent potential data exposure and review compensating controls for exposed systems.

Defensive priority

Authenticated users with low privileges may be able to restore deleted documents. Organizations using Frappe should prioritize patching to prevent potential data exposure.

Recommended defensive actions

  • Review and apply patches for Frappe versions 15.110.0 and 16.20.0 or later
  • Verify system configurations and user permissions
  • Monitor for suspicious activity related to document restoration
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected systems and potential impact require further verification. Organizations should verify their deployments, review configurations, and monitor for suspicious activity related to document restoration. Defensive priorities include patching, compensating controls, and exposure review.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:08.960Z and has not been modified since then.