Description
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
Published: 2026-09-20
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in whitelisted timesheet endpoints of Frappe ERPNext. The endpoints fail to enforce doctype permissions, allowing an authenticated user to call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet. This leads to enumeration and retrieval of billable time logs, including project names, billing amounts and work descriptions, without proper authorization checks. The result is a breach of confidentiality of sensitive business information.

Affected Systems

The vulnerability affects all Frappe ERPNext deployments running versions prior to 15.121.0 and all 16.x releases prior to 16.34.0. These versions are available from the ERPNext product line.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score is not available, and the issue is not in the CISA KEV catalog, suggesting that while exploitation is possible, it may not be widely leveraged yet. Attackers must first authenticate to the system, and then they can use the exposed endpoints to access private timesheet data. Because the endpoints lack proper authorization, any authenticated user with access to the ERPNext interface can potentially disclose sensitive time-tracking and billing information.

Generated by OpenCVE AI on September 20, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Frappe ERPNext to version 15.121.0 or later 16.34.0 or higher
  • If upgrade is not immediately feasible, restrict user roles that can access the whitelisted timesheet endpoints and enforce doctype permissions manually
  • Conduct an audit of timesheet data to detect any unauthorized access and monitor logs for anomalies

Generated by OpenCVE AI on September 20, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
Title Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints
First Time appeared Frappe
Frappe erpnext
Weaknesses CWE-862
CPEs cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*
Vendors & Products Frappe
Frappe erpnext
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T11:56:08.372Z

Reserved: 2026-09-20T11:41:41.230Z

Link: CVE-2026-94113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-20T12:17:07.117

Modified: 2026-09-20T12:17:07.250

Link: CVE-2026-94113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:45:07Z

Weaknesses