{"id":"CVE-2026-66000","summary":"Frappe: Unrestricted access to Document Follow APIs","details":"Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.","aliases":["GHSA-wcm9-vvcc-r8pr"],"modified":"2026-08-09T03:47:27.087645721Z","published":"2026-08-07T18:25:11.671Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66000.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66000.json"},{"type":"ADVISORY","url":"https://github.com/frappe/frappe/security/advisories/GHSA-wcm9-vvcc-r8pr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66000"},{"type":"FIX","url":"https://github.com/frappe/frappe/commit/0914acb998004b3878eb5cf57b765115305b49a6"},{"type":"FIX","url":"https://github.com/frappe/frappe/commit/b02c1aec2c75eb0819cc6730dd230c2acb0fa60d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/frappe","events":[{"introduced":"a2ab8a654ad157cd377242e9481f600e37361049"},{"introduced":"b8c1f492c492f7cbbfd3cc768234fbb244fd3737"},{"fixed":"ba18090b141740e75d52aa97bfc525ff2f831f6c"},{"fixed":"48a624796afc1431268e72eea38ca256b450ab73"},{"fixed":"0914acb998004b3878eb5cf57b765115305b49a6"},{"fixed":"b02c1aec2c75eb0819cc6730dd230c2acb0fa60d"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"16.0.0-beta.1"},{"fixed":"16.19.0"},{"introduced":"15.0.0"},{"fixed":"15.109.0"}]}}],"versions":["v15.108.0","v16.18.3","v15.107.5","v16.18.2","v16.18.1","v15.107.4","v15.107.3","v16.18.0","v15.107.2","v16.17.5","v16.17.4","v16.17.3","v15.107.1","v15.107.0","v16.17.2","v16.17.1","v16.17.0","v15.106.0","v16.16.0","v15.105.0","v16.15.0","v15.104.0","v16.14.0","v16.13.0","v15.103.3","v15.103.2","v16.12.2","v16.12.1","v15.103.1","v16.12.0","v15.103.0","v15.102.1","v16.11.0","v15.102.0","v15.101.5","v16.10.10","v16.10.9","v15.101.4","v16.10.8","v16.10.7","v15.101.3","v15.101.2","v15.101.1","v16.10.6","v16.10.5","v16.10.4","v15.101.0","v16.10.3","v16.10.2","v16.10.1","v16.10.0","v15.100.1","v16.9.0","v16.8.1","v16.8.0","v16.7.0","v15.100.0","v16.6.0","v16.5.0","v15.99.0","v15.98.1","v16.4.1","v15.98.0","v16.4.0","v16.3.0","v16.2.1","v15.97.0","v16.2.0","v15.96.0","v16.1.1","v16.1.0","v15.95.0","v16.0.0","v15.94.1","v15.94.0","v15.93.0","v15.92.0","v15.91.3","v15.91.2","v16.0.0-beta.1","v15.91.1","v15.91.0","v15.90.1","v15.90.0","v15.89.0","v15.88.2","v15.88.1","v15.88.0","v15.87.0","v15.86.0","v15.85.1","v15.85.0","v15.84.0","v15.83.0","v15.82.1","v15.82.0","v15.81.1","v15.81.0","v15.80.0","v15.79.0","v15.78.1","v15.78.0","v15.77.0","v15.76.0","v15.75.0","v15.74.2","v15.74.1","v15.74.0","v15.73.0","v15.72.5","v15.72.4","v15.72.3","v15.72.2","v15.72.1","v15.72.0","v15.71.0","v15.70.0","v15.69.3","v15.69.2","v15.69.1","v15.69.0","v15.68.1","v15.68.0","v15.67.0","v15.66.1","v15.66.0","v15.65.2","v15.65.1","v15.65.0","v15.64.0","v15.63.1","v15.63.0","v15.62.0","v15.61.0","v15.60.0","v15.59.0","v15.58.1","v15.58.0","v15.57.2","v15.57.1","v15.57.0","v15.56.1","v15.56.0","v15.55.2","v15.55.1","v15.55.0","v15.54.1","v15.54.0","v15.53.0","v15.52.0","v15.51.2","v15.51.1","v15.51.0","v15.50.1","v15.50.0","v15.49.1","v15.49.0","v15.48.1","v15.48.0","v15.47.2","v15.47.1","v15.47.0","v15.46.0","v15.45.1","v15.45.0","v15.44.2","v15.44.1","v15.44.0","v15.43.0","v15.42.0","v15.41.0","v15.40.6","v15.40.5","v15.40.4","v15.40.3","v15.40.2","v15.40.1","v15.40.0","v15.39.2","v15.39.1","v15.39.0","v15.38.0","v15.37.0","v15.36.1","v15.36.0","v15.35.0","v15.34.1","v15.34.0","v15.33.3","v15.33.2","v15.33.1","v15.33.0","v15.32.0","v15.31.0","v15.30.0","v15.29.2","v15.29.1","v15.29.0","v15.28.0","v15.27.0","v15.26.0","v15.25.0","v15.24.1","v15.24.0","v15.23.0","v15.22.0","v15.21.0","v15.20.0","v15.19.1","v15.19.0","v15.18.2","v15.18.1","v15.18.0","v15.17.3","v15.17.2","v15.17.1","v15.17.0","v15.16.1","v15.16.0","v15.15.0","v15.14.1","v15.14.0","v15.13.0","v15.12.0","v15.11.0","v15.10.0","v15.9.0","v15.8.1","v15.8.0","v15.7.0","v15.6.1","v15.6.0","v15.5.0","v15.4.1","v15.4.0","v15.3.0","v15.2.1","v15.2.0","v15.1.0","v15.0.2","v15.0.1","v15.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66000.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}