Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94113.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "15.121.0"
},
{
"introduced": "16.0.0"
},
{
"fixed": "16.34.0"
}
],
"source": "AFFECTED_FIELD"
}