CVE-2026-66000

LOW

Frappe: Unrestricted access to Document Follow APIs

Title source: cna
STIX 2.1

Description

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

Scores

CVSS v4 2.3
EPSS 0.0026
EPSS Percentile 17.4%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
frappe/frappe >= 15.0.0, < 15.109.0
frappe/frappe >= 16.0.0-beta.1, < 16.19.0
Published Aug 07, 2026
Tracked Since Aug 08, 2026