Description
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address.
The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to:

* Obtain the authentication OTP;
* Impersonate someone else in the registration process;
* Register accounts using other people's email addresses without access to the mailbox;
* Indirectly confirm the existence of already registered email addresses.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Impersonation and unauthorized registration through OTP exploitation
Action: Apply Patch
AI Analysis

Impact

A flaw in the authentication process of Frappe Cloud and ERPNext permits an unauthenticated attacker to supply more than one email address to the signup API. The system treats the entire value as a list of recipients, sending a one‑time password (OTP) to every address without ensuring each is a valid target. By capturing the OTP, an attacker can impersonate another user, register accounts using addresses they do not control, or confirm that an email address is already registered. This weakness is classified as CWE‑290, reflecting insufficient user authentication data validation.

Affected Systems

The vulnerability affects all releases of Frappe Technologies' products before the 23.03.2026 release, including Frappe Cloud and ERPNext. Users running any of these older versions should verify their installed component versions and seek an update.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity level, while the absence of an EPSS rating and non‑listing in KEV suggest there is currently no documented exploitation. Nonetheless, the anonymous nature of the web API means a remote attacker can easily construct the payload, and the impact of compromising OTP credentials is high. The risk therefore lies in potential account takeovers and the ability to perform bulk user verification without mailbox access.

Generated by OpenCVE AI on October 8, 2026 at 10:21 UTC.

Remediation

Vendor Solution

The vulnerability has been fixed by Frappe Technologies.


OpenCVE Recommended Actions

  • Apply the latest Frappe Technologies release that contains the authentication fix
  • Configure the signup API to enforce single, validated email addresses and reject payloads containing multiple addresses
  • If a patch cannot be applied immediately, temporarily disable unauthenticated access to the /api/method/press.api.account.signup endpoint and monitor logs for suspicious OTP transmissions

Generated by OpenCVE AI on October 8, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address. The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to: * Obtain the authentication OTP; * Impersonate someone else in the registration process; * Register accounts using other people's email addresses without access to the mailbox; * Indirectly confirm the existence of already registered email addresses.
Title Authentication bypass in multiple products from Frappe Technologies
First Time appeared Frappe Technologies
Frappe Technologies frappe Technologies
Weaknesses CWE-290
CPEs cpe:2.3:a:frappe_technologies:frappe_technologies:version_before_23_03_2026:*:*:*:*:*:*:*
Vendors & Products Frappe Technologies
Frappe Technologies frappe Technologies
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Frappe Technologies Frappe Technologies
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-08T08:44:19.546Z

Reserved: 2026-03-26T13:21:21.030Z

Link: CVE-2026-4894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T09:16:41.477

Modified: 2026-10-08T09:16:41.477

Link: CVE-2026-4894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T10:30:16Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing