Field-Level Permissions Bypass in Frappe Web Application Framework
CVE-2026-66059
5.3MEDIUM
What is CVE-2026-66059?
A field-level permissions bypass was identified within the Frappe web application framework, allowing unauthorized access to restricted DocType fields prior to versions 16.23.0 and 15.112.0. This security flaw may enable attackers to view or manipulate sensitive information that should be protected by field-level permissions. Users are advised to upgrade to the patched versions immediately to mitigate the risks associated with this vulnerability.
Affected Version(s)
frappe >= 16.0.0-beta.1, < 16.20.0 < 16.0.0-beta.1, 16.20.0
frappe < 15.112.0 < 15.112.0
