MEDIUM
Frappe Technologies
CVE published 2026-10-08
CVE-2026-4894
CVE-2026-4894 is an authentication bypass vulnerability in Frappe Technologies products. The vulnerability occurs in the /api/method/press.api.account.signup endpoint, allowing an unauthenticated remote attacker to add multiple email addresses and obtain the authentication OTP, impersonate someone else in the registration process, register accounts using other people's email addresses without access to th [truncated]