
⚠️⚠️ CVE-2026-39352 (CVSS 8.7): Path traversal may allow unauthenticated arbitrary file read on internet-facing Frappe-based ERP surfaces (e.g. ERPNext). 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJFUlBOZXh0Ig== 🎯115.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="ERPNext" 🔖Refer: https://github.com/frappe/frappe/security/advisories/GHSA-67rf-pxgh-vfqv #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
A CVE-2026-39352 path traversal flaw in Frappe ERPs is highlighted with a CVSS 8.7 score, and a link to a security advisory suggests a vendor-provided patch exists.
