CVE-2026-66000: Frappe: Unrestricted access to Document Follow APIs
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.23.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.112.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66000?
CVE-2026-66000 has been assigned a risk score of 33, indicating a moderate concern.
How do I fix CVE-2026-66000?
To fix CVE-2026-66000, upgrade to Frappe version 16.23.0 or later, or 15.112.0 or later.
What does CVE-2026-66000 affect?
CVE-2026-66000 affects the Document Follow APIs in Frappe prior to version updates specified.
What are the implications of CVE-2026-66000?
CVE-2026-66000 allows users with revoked or reduced access to continue receiving document data by email, which can lead to unauthorized information exposure.
When was CVE-2026-66000 published?
CVE-2026-66000 was published on August 7, 2026.