CVE-2026-66000

Source
https://cve.org/CVERecord?id=CVE-2026-66000
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66000.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66000
Aliases
  • GHSA-wcm9-vvcc-r8pr
Published
2026-08-07T18:25:11.671Z
Modified
2026-08-09T03:47:27.087645721Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Frappe: Unrestricted access to Document Follow APIs
Details

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66000.json"
}
References

Affected packages

Git / github.com/frappe/frappe

Affected ranges

Type
GIT
Repo
https://github.com/frappe/frappe
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "16.0.0-beta.1"
        },
        {
            "fixed": "16.19.0"
        },
        {
            "introduced": "15.0.0"
        },
        {
            "fixed": "15.109.0"
        }
    ]
}

Affected versions

v15.*
v15.0.0
v15.0.1
v15.0.2
v15.1.0
v15.10.0
v15.100.0
v15.100.1
v15.101.0
v15.101.1
v15.101.2
v15.101.3
v15.101.4
v15.101.5
v15.102.0
v15.102.1
v15.103.0
v15.103.1
v15.103.2
v15.103.3
v15.104.0
v15.105.0
v15.106.0
v15.107.0
v15.107.1
v15.107.2
v15.107.3
v15.107.4
v15.107.5
v15.108.0
v15.11.0
v15.12.0
v15.13.0
v15.14.0
v15.14.1
v15.15.0
v15.16.0
v15.16.1
v15.17.0
v15.17.1
v15.17.2
v15.17.3
v15.18.0
v15.18.1
v15.18.2
v15.19.0
v15.19.1
v15.2.0
v15.2.1
v15.20.0
v15.21.0
v15.22.0
v15.23.0
v15.24.0
v15.24.1
v15.25.0
v15.26.0
v15.27.0
v15.28.0
v15.29.0
v15.29.1
v15.29.2
v15.3.0
v15.30.0
v15.31.0
v15.32.0
v15.33.0
v15.33.1
v15.33.2
v15.33.3
v15.34.0
v15.34.1
v15.35.0
v15.36.0
v15.36.1
v15.37.0
v15.38.0
v15.39.0
v15.39.1
v15.39.2
v15.4.0
v15.4.1
v15.40.0
v15.40.1
v15.40.2
v15.40.3
v15.40.4
v15.40.5
v15.40.6
v15.41.0
v15.42.0
v15.43.0
v15.44.0
v15.44.1
v15.44.2
v15.45.0
v15.45.1
v15.46.0
v15.47.0
v15.47.1
v15.47.2
v15.48.0
v15.48.1
v15.49.0
v15.49.1
v15.5.0
v15.50.0
v15.50.1
v15.51.0
v15.51.1
v15.51.2
v15.52.0
v15.53.0
v15.54.0
v15.54.1
v15.55.0
v15.55.1
v15.55.2
v15.56.0
v15.56.1
v15.57.0
v15.57.1
v15.57.2
v15.58.0
v15.58.1
v15.59.0
v15.6.0
v15.6.1
v15.60.0
v15.61.0
v15.62.0
v15.63.0
v15.63.1
v15.64.0
v15.65.0
v15.65.1
v15.65.2
v15.66.0
v15.66.1
v15.67.0
v15.68.0
v15.68.1
v15.69.0
v15.69.1
v15.69.2
v15.69.3
v15.7.0
v15.70.0
v15.71.0
v15.72.0
v15.72.1
v15.72.2
v15.72.3
v15.72.4
v15.72.5
v15.73.0
v15.74.0
v15.74.1
v15.74.2
v15.75.0
v15.76.0
v15.77.0
v15.78.0
v15.78.1
v15.79.0
v15.8.0
v15.8.1
v15.80.0
v15.81.0
v15.81.1
v15.82.0
v15.82.1
v15.83.0
v15.84.0
v15.85.0
v15.85.1
v15.86.0
v15.87.0
v15.88.0
v15.88.1
v15.88.2
v15.89.0
v15.9.0
v15.90.0
v15.90.1
v15.91.0
v15.91.1
v15.91.2
v15.91.3
v15.92.0
v15.93.0
v15.94.0
v15.94.1
v15.95.0
v15.96.0
v15.97.0
v15.98.0
v15.98.1
v15.99.0
v16.*
v16.0.0
v16.0.0-beta.1
v16.1.0
v16.1.1
v16.10.0
v16.10.1
v16.10.10
v16.10.2
v16.10.3
v16.10.4
v16.10.5
v16.10.6
v16.10.7
v16.10.8
v16.10.9
v16.11.0
v16.12.0
v16.12.1
v16.12.2
v16.13.0
v16.14.0
v16.15.0
v16.16.0
v16.17.0
v16.17.1
v16.17.2
v16.17.3
v16.17.4
v16.17.5
v16.18.0
v16.18.1
v16.18.2
v16.18.3
v16.2.0
v16.2.1
v16.3.0
v16.4.0
v16.4.1
v16.5.0
v16.6.0
v16.7.0
v16.8.0
v16.8.1
v16.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66000.json"