Impact
A flaw in the authentication process of Frappe Cloud and ERPNext permits an unauthenticated attacker to supply more than one email address to the signup API. The system treats the entire value as a list of recipients, sending a one‑time password (OTP) to every address without ensuring each is a valid target. By capturing the OTP, an attacker can impersonate another user, register accounts using addresses they do not control, or confirm that an email address is already registered. This weakness is classified as CWE‑290, reflecting insufficient user authentication data validation.
Affected Systems
The vulnerability affects all releases of Frappe Technologies' products before the 23.03.2026 release, including Frappe Cloud and ERPNext. Users running any of these older versions should verify their installed component versions and seek an update.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity level, while the absence of an EPSS rating and non‑listing in KEV suggest there is currently no documented exploitation. Nonetheless, the anonymous nature of the web API means a remote attacker can easily construct the payload, and the impact of compromising OTP credentials is high. The risk therefore lies in potential account takeovers and the ability to perform bulk user verification without mailbox access.
OpenCVE Enrichment