PatchSiren cyber security CVE debrief
CVE-2026-47765 frappe CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:08.960Z and has not been modified since then. Frappe versions 15.110.0 and 16.20.0 or later address the issue. Organizations using Frappe should prioritize patching to prevent potential data exposure and review compensating controls for exposed systems. The vulnerability affects the restore and bulk_restore endpoints, allowing authenticated users to restore deleted documents without required authorization. This issue is fixed in Frappe versions 15.110.0 and 16.20.0. Organizations should verify their deployments, review configurations, and monitor for suspicious activity related to document restoration.
- Vendor
- frappe
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Organizations using Frappe, especially those with multiple users or sensitive data, should be aware of this vulnerability and take steps to patch their systems. Affected operators, platforms, and security teams should review configurations, monitor for suspicious activity, and plan vendor-supported updates or mitigations.
Technical summary
The restore and bulk_restore endpoints in Frappe do not apply appropriate document permission checks. This allows an authenticated user to restore deleted documents without the required authorization. The issue is fixed in Frappe versions 15.110.0 and 16.20.0. Organizations using Frappe should prioritize patching to prevent potential data exposure and review compensating controls for exposed systems.
Defensive priority
Authenticated users with low privileges may be able to restore deleted documents. Organizations using Frappe should prioritize patching to prevent potential data exposure.
Recommended defensive actions
- Review and apply patches for Frappe versions 15.110.0 and 16.20.0 or later
- Verify system configurations and user permissions
- Monitor for suspicious activity related to document restoration
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected systems and potential impact require further verification. Organizations should verify their deployments, review configurations, and monitor for suspicious activity related to document restoration. Defensive priorities include patching, compensating controls, and exposure review.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:08.960Z and has not been modified since then.