CVE-2026-94113

high

Description

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.

References

https://www.vulncheck.com/advisories/frappe-erpnext-before-15.121.0-and-16.34.0-missing-authorization-in-timesheet-endpoints

https://github.com/frappe/erpnext/security/advisories/GHSA-9vph-hqmm-g7hq

https://github.com/frappe/erpnext/pull/58576

https://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41

https://github.com/frappe/erpnext/commit/c656497aac76af82eea028e3e8cb8d5380385f0f

Details

Source: Mitre, NVD

Published: 2026-09-20

Updated: 2026-09-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00242