Field-Level Permissions Bypass in Frappe Web Application Framework
CVE-2026-66059

5.3MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-66059?

A field-level permissions bypass was identified within the Frappe web application framework, allowing unauthorized access to restricted DocType fields prior to versions 16.23.0 and 15.112.0. This security flaw may enable attackers to view or manipulate sensitive information that should be protected by field-level permissions. Users are advised to upgrade to the patched versions immediately to mitigate the risks associated with this vulnerability.

Affected Version(s)

frappe >= 16.0.0-beta.1, < 16.20.0 < 16.0.0-beta.1, 16.20.0

frappe < 15.112.0 < 15.112.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.