Description
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.
Published: 2026-08-07
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Frappe, a full‑stack web framework, failed to re‑evaluate recipient permissions when generating document follow notifications. Users whose access had been revoked or reduced could still receive document data by email, enabling an unauthorized disclosure of confidential content. The weakness is an access control bypass (CWE‑863) that exposes sensitive information to unintended recipients.

Affected Systems

The issue affects the frappe:frappe application. It applies to all releases prior to 16.23.0 and 15.112.0; these specific versions contain the vulnerable logic. Use newer releases to eliminate the flaw.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity problem, and no EPSS score is available. Because the flaw exists only in the notification generation path, an attacker would need to have a legitimate user account, trigger a document follow event, or rely on an existing event, but could not directly code arbitrary requests. Consequently, the exploitability is limited and the impact is confined to recipients with revoked or reduced permissions. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 7, 2026 at 19:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Frappe to version 16.23.0 or 15.112.0 or later to apply the vendor fix.
  • Revoke or remove permissions for users who should no longer receive document that are still present in follow notifications.
  • Disable document follow email notifications for all accounts with restricted access or adjust the template to omit sensitive data.

Generated by OpenCVE AI on August 7, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe frappe
Vendors & Products Frappe
Frappe frappe

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.
Title Frappe: Unrestricted access to Document Follow APIs
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-07T18:39:50.944Z

Reserved: 2026-07-23T18:54:15.833Z

Link: CVE-2026-66000

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T19:30:04Z

Weaknesses