Sceawere

Vulnerability Detail

CVE-2026-108734UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Frappe CRM Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
frappe
Product
crm
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:17.627Z",
  "pubdate": "2026-10-11T13:17:17.627Z",
  "executiveSummary": "This vulnerability is a Missing Authorization flaw within the Frappe CRM application, specifically affecting the crm.api.doc.get_linked_docs_of_document function.\nThe issue permits authenticated users to bypass standard access control mechanisms, allowing them to retrieve linked document metadata and sensitive information for objects they are not authorized to access.\nThe vulnerability affects Frappe CRM versions 1.49.0 through 1.87.0.\nSuccessful exploitation allows an authenticated attacker to perform unauthorized information disclosure, specifically targeting linked call logs, organization associations, and internal mention notification content.\nThe primary risk implication is the compromise of sensitive business data, including personally identifiable information (PII) such as phone numbers and private internal communications.\nExploitation requires the attacker to possess an authenticated session within the application, though no elevated privileges are required to leverage the flaw.\nThe lack of robust server-side permission checks during the execution of linked document retrieval functions constitutes a significant failure in the application's authorization logic.",
  "technicalDetails": "The vulnerability resides within the crm.api.doc.get_linked_docs_of_document function, which is designed to aggregate and return documents linked to a specific entity within the CRM ecosystem.\nThe root cause of this vulnerability is a failure to enforce authorization checks against the requested resource during the document retrieval process. While the function correctly receives input parameters identifying a document, it fails to perform a 'has_permission' check or verify the requesting user's access rights to the target object before querying and returning the linked document list.\nIn a secure implementation, the framework should validate the session user’s access level against the target document before executing queries that surface associated data. Because this validation step is absent, the backend assumes that any request from an authenticated user is implicitly authorized for the linked resources associated with the target entity.\nAn attacker can exploit this flaw by submitting specifically crafted requests targeting documents—such as leads, deals, comments, or user profiles—to which they would otherwise be restricted. By invoking the crm.api.doc.get_linked_docs_of_document endpoint, the attacker forces the system to perform a look-up and return references and metadata for documents that are linked to the target object.\nThe attack flow follows a predictable sequence: First, the attacker identifies a target document ID (e.g., a restricted lead or deal record). Second, the attacker sends a request to the vulnerable API endpoint specifying that ID as the primary argument. Third, the backend, lacking internal permission gating, retrieves the linked records associated with that entity. Finally, the server returns the requested information—including phone numbers from call logs, organizational names associated with deals, and text contents of mention notifications—directly to the attacker's session.\nThis behavior facilitates the unauthorized extraction of sensitive metadata that would be otherwise inaccessible to low-privileged users. The impact is significant, as it exposes the relational data structure of the CRM, effectively circumventing the application's intended access control matrix and enabling lateral information gathering across the organization's database records.\nThe vulnerability is persistent across all versions from 1.49.0 to 1.87.0, and requires no specific network-level bypass, as the vulnerability exists at the application layer."
}
CVE-2026-108734: Frappe CRM Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere