CVE-2026-53761 Details
Description
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0.
An authentication bypass vulnerability has been identified in Frappe CRM versions prior to 1.73.0. This vulnerability allows unauthorized access through logged invitation keys in the crm/api endpoint. The issue arises because invitation keys, once accepted, can be exploited to bypass authentication.
Users can upgrade to Frappe CRM version 1.73.0 or later to address this vulnerability. For those who have already accepted invitations, it is recommended to manually nullify or randomize the key field for all rows in the tabCRM Invitation table where the status is set to Accepted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/frappe/crm/releases/tag/v1.73.0 | [email protected] | Release NotesVendor |
| https://github.com/frappe/crm/security/advisories/GHSA-wqrv-q8m5-qr77 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Frappe CRM | < v1.72.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion