Email Notification Flaw in Frappe Framework
CVE-2026-66000
2.3LOW
What is CVE-2026-66000?
The Frappe Framework suffers from an improper access control issue in its Document Follow notification feature. Prior to release versions 16.23.0 and 15.112.0, the application failed to re-evaluate a user's permissions when sending notifications about document changes. This means that users who previously had access revoked or reduced might still receive confidential document-related emails, thereby exposing sensitive information inadvertently. The vulnerability has been addressed in the mentioned versions, enhancing the security around document notifications.
Affected Version(s)
frappe >= 16.0.0-beta.1, < 16.19.0 < 16.0.0-beta.1, 16.19.0
frappe >= 15.0.0, < 15.109.0 < 15.0.0, 15.109.0
