CVE-2026-66058: Frappe: Unrestricted access to a Document Follow API
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (updatefollow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.20.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.112.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66058?
CVE-2026-66058 has a risk score of 23.
How do I fix CVE-2026-66058?
CVE-2026-66058 can be fixed by upgrading to Frappe versions 16.20.0 or 15.112.0.
What does the vulnerability CVE-2026-66058 affect?
CVE-2026-66058 affects the Document Follow API within the Frappe Framework.
Who is affected by CVE-2026-66058?
CVE-2026-66058 affects authenticated users of Frappe versions prior to 16.20.0 and 15.112.0.
What is the nature of CVE-2026-66058?
CVE-2026-66058 involves unrestricted access to a Document Follow API.