PT-2026-34841 · Frappe · Press

T3L3Sc0P3

·

Published

2026-04-24

·

Updated

2026-04-30

·

CVE-2026-41317

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Press (affected versions not specified)
Description Press, a Frappe custom app used for managing infrastructure, subscriptions, marketplace, and software-as-a-service (SaaS), contains a flaw in the 'press.api.account.create api secret' endpoint. This endpoint allows database writes and is accessible via the GET method, making it susceptible to Cross-Site Request Forgery (CSRF) style exploits, where an attacker could trick a user into performing unintended actions.
Recommendations Restrict the 'press.api.account.create api secret' endpoint to only allow POST requests.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41317

Affected Products

Press