๐Ÿ” CVE Alert

CVE-2026-66000

UNKNOWN 0.0

Frappe: Unrestricted access to Document Follow APIs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

CWE CWE-863
Vendor frappe
Product frappe
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe

Be the first to know when new unknown vulnerabilities affecting frappe frappe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frappe / frappe
>= 16.0.0-beta.1, < 16.19.0 >= 15.0.0, < 15.109.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/frappe/security/advisories/GHSA-wcm9-vvcc-r8pr github.com: https://github.com/frappe/frappe/commit/0914acb998004b3878eb5cf57b765115305b49a6 github.com: https://github.com/frappe/frappe/commit/b02c1aec2c75eb0819cc6730dd230c2acb0fa60d