Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe frappe |
|
| Vendors & Products |
Frappe
Frappe frappe |
Thu, 20 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen state. An authenticated user can interact with documents or notes that the user cannot read, disclosing resource existence and modifying resource-associated metadata. No released fixed version is available as of this review. | |
| Title | Frappe: Missing authorization in toggle_like and mark_as_seen | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:03:07.692Z
Reserved: 2026-06-09T19:11:53.483Z
Link: CVE-2026-53569
Updated: 2026-08-20T19:03:03.408Z
Status : Received
Published: 2026-08-20T19:16:54.350
Modified: 2026-08-20T19:16:54.350
Link: CVE-2026-53569
No data.
OpenCVE Enrichment
Updated: 2026-08-20T19:30:05Z