CVE-2026-13227 | Frappe ERPNext up to 15.114.x/16.25.x Whitelisted API improper authorization

SecurityVulns

A vulnerability labeled as problematic has been found in Frappe ERPNext up to 15.114.x/16.25.x. Impacted is the function erpnext.crm.doctype.prospect.prospect.get_opportunities of the component Whitelisted API. The manipulation results in improper authorization.

This vulnerability is reported as CVE-2026-13227. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More