OAuth2 Vulnerability in Frappe Framework Affects User Data Security
CVE-2026-66001
8.5HIGH
What is CVE-2026-66001?
The Frappe Framework contains a vulnerability in its OAuth2 implementation, allowing the consent flow to proceed without properly enforcing POST requests, validating csrf_tokens, or scoping active OAuth token checks to the requesting client. This oversight can enable an attacker to manipulate an authenticated user's approvals, potentially granting unauthorized access to sensitive data and actions within the scope of permissions. Users are advised to upgrade to versions 15.114.0 or 16.26.0 to mitigate this risk.
Affected Version(s)
frappe < 15.114.0 < 15.114.0
frappe >= 16.0.0-beta.1, < 16.26.0 < 16.0.0-beta.1, 16.26.0
