CVE-2026-63654 | Frappe up to 16.31.0 Workflow frappe/model/workflow.py frappe.model.workflow.bulk_workflow_approval privileges management

SecurityVulns

A vulnerability classified as problematic has been found in Frappe up to 16.31.0. Affected by this vulnerability is the function frappe.model.workflow.bulk_workflow_approval of the file frappe/model/workflow.py of the component Workflow. The manipulation leads to improper privilege management.

This vulnerability is listed as CVE-2026-63654. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More