PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66000 frappe CVE debrief

CVE-2026-66000 is a low-severity vulnerability in the Frappe web application framework that allows users to continue receiving document data by email even after their access has been revoked or reduced. This issue was fixed in versions 16.23.0 and 15.112.0. The vulnerability exists in the Document Follow notification generation of Frappe, allowing users with revoked or reduced access to continue receiving document data by email. Defenders responsible for Frappe deployments should assess exposure and prioritize patching to prevent unauthorized access to sensitive document data.

Vendor
frappe
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-08
Advisory published
2026-08-07
Advisory updated
2026-09-08

Who should care

Defenders responsible for Frappe deployments should assess exposure and prioritize patching to prevent unauthorized access to sensitive document data. Defenders should prioritize verifying and applying the patches to prevent unauthorized access to sensitive document data. Operators, administrators, and security teams should review and update access controls for document data and monitor for unauthorized access to sensitive document data.

Why it matters

CVE-2026-66000 is a low-severity vulnerability in Frappe that allows users to continue receiving document data by email even after their access has been revoked or reduced. Defenders should prioritize verifying and applying patches to prevent unauthorized access to sensitive document data.

  • Potential unauthorized access to sensitive document data
  • Need to verify and apply patches to prevent exploitation
  • Possible email exposure for users with revoked or reduced access

Technical summary

The vulnerability exists in the Document Follow notification generation of Frappe, allowing users with revoked or reduced access to continue receiving document data by email. This issue was fixed in versions 16.23.0 and 15.112.0. Defenders should prioritize verifying and applying the patches to prevent unauthorized access to sensitive document data. The vulnerability allows users to continue receiving document data by email even after their access has been revoked or reduced, potentially leading to unauthorized access to sensitive document data.

Defensive priority

Defenders should prioritize verifying and applying the patches to prevent unauthorized access to sensitive document data.

Recommended defensive actions

  • Verify and apply patches to Frappe versions prior to 16.23.0 and 15.112.0
  • Review and update access controls for document data
  • Monitor for unauthorized access to sensitive document data
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed versions. The vulnerability allows users to continue receiving document data by email even after their access has been revoked or reduced. The issue was fixed in versions 16.23.0 and 15.112.0. Defenders should verify and apply patches to prevent unauthorized access to sensitive document data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66000 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66000

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66000 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66000

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.