Skip to main content
Vulnerability Database/CVE-2026-94113

CVE-2026-94113: Frappe ERPNext Information Disclosure

CVE-2026-94113 is an information disclosure flaw in Frappe ERPNext that allows authenticated attackers to access billable time logs without authorization. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-94113 Overview

CVE-2026-94113 is a missing authorization vulnerability [CWE-862] in Frappe ERPNext, an open-source enterprise resource planning platform. The flaw affects whitelisted timesheet endpoints that fail to enforce doctype-level permissions. Authenticated users can invoke get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet to enumerate billable time logs across the system. Exposed data includes project names, billing amounts, and work descriptions belonging to other users and projects. The issue affects Frappe ERPNext versions before 15.121.0 and 16.x versions before 16.34.0.

Critical Impact

Any authenticated ERPNext user can retrieve billable timesheet data (projects, rates, descriptions) belonging to other users, bypassing intended doctype access controls.

Affected Products

  • Frappe ERPNext versions before 15.121.0
  • Frappe ERPNext 16.x versions before 16.34.0
  • Deployments exposing whitelisted timesheet endpoints to authenticated users

Discovery Timeline

  • 2026-09-20 - CVE-2026-94113 published to NVD
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-94113

Vulnerability Analysis

ERPNext exposes several server-side methods through the Frappe whitelisting mechanism, which permits authenticated HTTP invocation. The vulnerable endpoints in erpnext/projects/doctype/timesheet/timesheet.py query the Timesheet and Timesheet Detail doctypes directly. The queries did not filter results based on the caller's doctype permissions. As a result, any authenticated session could retrieve time-tracking records regardless of ownership or project membership.

Disclosed fields include project identifiers, billing rates, billed amounts, and free-text work descriptions. This exposes financial data and internal project context that ERPNext's role-based access model normally restricts. The vulnerability is classified as information disclosure with no direct integrity or availability impact.

Root Cause

The root cause is missing authorization enforcement [CWE-862] inside whitelisted Python methods. Frappe's @frappe.whitelist() decorator only validates that a session is authenticated. Downstream doctype permissions must be enforced explicitly by the method. The timesheet endpoints issued raw frappe.qb queries against underlying tables without applying frappe.get_list permission filters.

Attack Vector

An attacker with any valid ERPNext account sends authenticated HTTP requests to the vulnerable method endpoints, for example /api/method/erpnext.projects.doctype.timesheet.timesheet.get_projectwise_timesheet_data. The server returns timesheet rows the caller is not authorized to view. Exploitation requires no user interaction and no elevated privileges beyond a standard login.

python
# Security patch adding permission-scoped filtering
# Source: https://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41
	tsd = frappe.qb.DocType("Timesheet Detail")
	ts = frappe.qb.DocType("Timesheet")

+	allowed_timesheets = frappe.get_list("Timesheet", pluck="name")
+	allowed_projects = frappe.get_list("Project", pluck="name")
+
+	if not allowed_timesheets:
+		return []
+
	query = (
		frappe.qb.from_(tsd)
		.inner_join(ts)

The patch calls frappe.get_list to derive the set of Timesheet and Project records the current user may access. The subsequent query is scoped to that allow-list, and the method returns an empty result when the user has no accessible timesheets.

Detection Methods for CVE-2026-94113

Indicators of Compromise

  • High-frequency authenticated calls to /api/method/erpnext.projects.doctype.timesheet.timesheet.get_projectwise_timesheet_data from a single session.
  • Requests to get_timesheet_detail_rate or get_timesheet originating from accounts that lack assigned projects or timesheet roles.
  • Anomalous JSON response sizes from timesheet endpoints indicating bulk enumeration.

Detection Strategies

  • Review Frappe application logs and NGINX or reverse proxy access logs for repeated api/method calls targeting timesheet functions.
  • Correlate calling user identity against expected role assignments; low-privilege users invoking billing-related methods warrant investigation.
  • Baseline normal timesheet API usage per role and alert on deviations in call volume or response payload size.

Monitoring Recommendations

  • Forward ERPNext HTTP access logs to a centralized log platform for retention and query.
  • Alert on any invocation of the three vulnerable methods by users outside the Projects, Accounts, or HR modules.
  • Track post-patch upgrade status of ERPNext instances across the environment to confirm remediation coverage.

How to Mitigate CVE-2026-94113

Immediate Actions Required

  • Upgrade Frappe ERPNext to version 15.121.0 or later on the 15.x branch.
  • Upgrade Frappe ERPNext to version 16.34.0 or later on the 16.x branch.
  • Audit user accounts and disable dormant or unnecessary logins that could be abused to query timesheet data.
  • Review historical access logs for signs of prior enumeration against the affected endpoints.

Patch Information

The fix is available in the upstream repository via GitHub ERPNext Commit Change and GitHub ERPNext Commit Update, merged through GitHub ERPNext Pull Request 58576. Additional context is published in GitHub Security Advisory GHSA-9vph-hqmm-g7hq and the VulnCheck Advisory for ERPNext.

Workarounds

  • Restrict network access to the ERPNext application so only trusted users can authenticate.
  • Reduce the number of accounts with any Timesheet or Projects module access until the patch is applied.
  • Monitor and rate-limit calls to /api/method/ endpoints at the reverse proxy layer.
bash
# Upgrade ERPNext using the bench CLI
bench switch-to-branch version-15 erpnext --upgrade
bench update --patch
bench --site all migrate
bench restart

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.