PatchSiren

Frappe Technologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Frappe Technologies CVE published 2026-10-08

CVE-2026-4894

CVE-2026-4894 is an authentication bypass vulnerability in Frappe Technologies products. The vulnerability occurs in the /api/method/press.api.account.signup endpoint, allowing an unauthenticated remote attacker to add multiple email addresses and obtain the authentication OTP, impersonate someone else in the registration process, register accounts using other people's email addresses without access to th [truncated]