User Enumeration Vulnerability in Frappe Web Application Framework
CVE-2026-66002
6.9MEDIUM
What is CVE-2026-66002?
The Frappe web application framework has a vulnerability that allows remote attackers to deduce the existence of registered users through inconsistent responses from public web forms. Specifically, prior to versions 15.115.0 and 16.27.0, the PersonalDataDownloadRequest class returned different response formats based on the status of the email address (registered vs unregistered). This flaw can be exploited by malicious actors to identify valid user accounts, potentially leading to further attacks or data breaches. The issue has been resolved in the latest patches.
Affected Version(s)
frappe < 15.115.0 < 15.115.0
frappe >= 16.0.0-beta.1, < 16.27.0 < 16.0.0-beta.1, 16.27.0
