User Enumeration Vulnerability in Frappe Web Application Framework
CVE-2026-66002

6.9MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-66002?

The Frappe web application framework has a vulnerability that allows remote attackers to deduce the existence of registered users through inconsistent responses from public web forms. Specifically, prior to versions 15.115.0 and 16.27.0, the PersonalDataDownloadRequest class returned different response formats based on the status of the email address (registered vs unregistered). This flaw can be exploited by malicious actors to identify valid user accounts, potentially leading to further attacks or data breaches. The issue has been resolved in the latest patches.

Affected Version(s)

frappe < 15.115.0 < 15.115.0

frappe >= 16.0.0-beta.1, < 16.27.0 < 16.0.0-beta.1, 16.27.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.