CVE-2026-94113
published 2026-09-20CVE-2026-94113: Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.42%
34.4th percentile
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| frappe | erpnext | < 15.121.0 | 15.121.0 |
| frappe | erpnext | >= 16.0.0 < 16.34.0 | 16.34.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions.
ghsa_unreviewed·2026-09-20
CVE-2026-94113 [HIGH] CWE-862 Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions.
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
VulDB
Frappe ERPNext up to 15.120.x/16.33.x Timesheet Endpoints information disclosure
vuldb·2026-09-20·CVSS 6.5
CVE-2026-94113 [MEDIUM] Frappe ERPNext up to 15.120.x/16.33.x Timesheet Endpoints information disclosure
A vulnerability labeled as problematic has been found in Frappe ERPNext up to 15.120.x/16.33.x. The affected element is the function get_projectwise_timesheet_data/get_timesheet_detail_rate/get_timesheet of the component Timesheet Endpoints. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-94113. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/frappe/erpnext/commit/c656497aac76af82eea028e3e8cb8d5380385f0fhttps://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41https://github.com/frappe/erpnext/pull/58576https://github.com/frappe/erpnext/security/advisories/GHSA-9vph-hqmm-g7hqhttps://www.vulncheck.com/advisories/frappe-erpnext-before-15.121.0-and-16.34.0-missing-authorization-in-timesheet-endpoints
2026-09-20
Published