github.comConfirmation
https://github.com/frappe/frappe/security/advisories/GHSA-fgx7-fvpx-mw3g CVE-2026-66058
MEDIUM
Frappe: Unrestricted access to a Document Follow API
Record summary
CVE-2026-66058 has a selected CVSS score of 5.3 (medium).
Description
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
frappeBrowse frappe / frappe | CVE List | >= 16.0.0-beta.1, < 16.20.0 | affected |
| < 15.112.0 | affected |