Description
Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Linked Documents
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in a missing authorization check for the get_linked_docs_of_document endpoint in Frappe CRM. Users who are already authenticated can request linked documents for records they should not otherwise have visibility into, such as leads, deals, comments or user profiles. By enumerating these records the attacker can retrieve sensitive details such as call log phone numbers, associated organizations, and notification text, potentially compromising privacy and business data.

Affected Systems

Frappe CRM versions 1.49.0 through 1.87.0 are affected. The issue is present in the crm.api.doc module of these releases.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. Because the vulnerability is only exploitable by authenticated users, the attack vector is internal or privileged accounts; external unauthenticated attackers cannot exploit it. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Nonetheless, any organization that relies on Frappe CRM for managing sensitive customer data should treat this as a significant privacy risk and consider it for prioritization.

Generated by OpenCVE AI on October 11, 2026 at 13:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Frappe CRM to a version that includes the authorization fix, removing the flaw that allows unauthenticated document reads.
  • If an immediate upgrade is not feasible, restrict the "Everyone" or similar global roles that may access get_linked_docs_of_document by reviewing and tightening role-based permissions so only privileged users can request linked documents.
  • Implement monitoring of the get_linked_docs_of_document API to detect unexpected or excessive calls, and audit logs for anomalous access patterns to sensitive records.

Generated by OpenCVE AI on October 11, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe crm
Vendors & Products Frappe
Frappe crm

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.
Title Frappe CRM 1.49.0 through 1.87.0 Missing Authorization via get_linked_docs_of_document
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:41.052Z

Reserved: 2026-10-11T01:52:48.413Z

Link: CVE-2026-108734

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:17.627

Modified: 2026-10-11T13:17:17.627

Link: CVE-2026-108734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses