CVE-2026-66059: Frappe: Field-level permission bypass via Document Follow
Published Aug 7, 2026
·Updated
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.
Affected Software
2 affected components
Frappe Frappe Framework<16.20.0
Frappe Frappe Framework<15.112.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.23.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.112.0
Event History
Aug 7, 2026
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the risk level of CVE-2026-66059?
The risk level of CVE-2026-66059 is 45.
2
What does CVE-2026-66059 affect?
CVE-2026-66059 affects the Frappe Framework prior to versions 16.20.0 and 15.112.0.
3
What type of vulnerability is CVE-2026-66059?
CVE-2026-66059 is a field-level permission bypass vulnerability.
4
How do I fix CVE-2026-66059?
To fix CVE-2026-66059, upgrade to Frappe Framework versions 16.23.0 or 15.112.0.
5
What is the impact of CVE-2026-66059?
The impact of CVE-2026-66059 is that it exposes restricted DocType fields.