CVE-2026-66000
Received Received - Intake

Document Follow Permission Bypass in Frappe Framework

Vulnerability report for CVE-2026-66000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: GitHub, Inc.

Description

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
frappe frappe to 16.23.0|end_excluding=15.112.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stale authorization issue in the Document Follow feature of the Frappe Framework. It allows users whose document access was revoked or reduced to continue receiving email notifications with document data even after their permissions are removed. The system fails to re-evaluate permissions before sending notifications, leading to unauthorized data exposure.

Detection Guidance

Check Frappe framework versions with: bench version. If running versions before 16.23.0 or 15.112.0, the system is vulnerable. Review Document Follow records for users with revoked permissions still receiving notifications.

Impact Analysis

If you use Frappe Framework versions prior to 16.23.0 or 15.112.0, users who no longer have access to certain documents may still receive sensitive document updates via email. This could lead to unauthorized access to confidential or restricted information.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by exposing sensitive data to unauthorized users. GDPR requires strict access controls and data protection, while HIPAA mandates safeguards to prevent unauthorized access to protected health information. The flaw undermines these controls.

Mitigation Strategies

Upgrade Frappe to version 16.23.0 or 15.112.0 or later immediately. No workarounds exist; updating is the only mitigation. Verify Document Follow permissions after upgrade to ensure revoked access is properly handled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart