EUVD Vulnerability Catalog
EUVD-2026-94811
Severity: MEDIUM
Base Score: 6.9
CVSS Version: 4.0
Vulnerability Description
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address.
The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to:
* Obtain the authentication OTP;
* Impersonate someone else in the registration process;
* Register accounts using other people's email addresses without access to the mailbox;
* Indirectly confirm the existence of already registered email addresses.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Attack Requirements (AT): None
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Vulnerability Confidentiality Impact (VC): Low
▪
Vulnerability Integrity Impact (VI): Low
▪
Vulnerability Availability Impact (VA): None
▪
Subsequent Confidentiality Impact (SC): None
▪
Subsequent Integrity Impact (SI): None
▪
Subsequent Availability Impact (SA): None
Affected Vendors & Systems
Vendor
Frappe Technologies
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
INCIBE
EPSS Probability
0
Known Aliases
CVE-2026-4894
GHSA-44qm-r6v9-65h7
Published On
2026-10-08
Last Updated
2026-10-08