Email Notification Flaw in Frappe Framework
CVE-2026-66000

2.3LOW

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-66000?

The Frappe Framework suffers from an improper access control issue in its Document Follow notification feature. Prior to release versions 16.23.0 and 15.112.0, the application failed to re-evaluate a user's permissions when sending notifications about document changes. This means that users who previously had access revoked or reduced might still receive confidential document-related emails, thereby exposing sensitive information inadvertently. The vulnerability has been addressed in the mentioned versions, enhancing the security around document notifications.

Affected Version(s)

frappe >= 16.0.0-beta.1, < 16.19.0 < 16.0.0-beta.1, 16.19.0

frappe >= 15.0.0, < 15.109.0 < 15.0.0, 15.109.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.