PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66002 frappe CVE debrief

The Frappe framework, a full-stack web application framework, has a vulnerability that allows remote attackers to enumerate registered users. This issue arises from distinguishable response shapes for registered and unregistered email addresses in the public request-data web form and PersonalDataDownloadRequest class. The vulnerability is fixed in versions 15.115.0 and 16.27.0. Organizations should be aware of this issue and take steps to mitigate it, as it poses a medium-priority risk with a CVSS score of 6.9.

Vendor
frappe
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-20
Original CVE updated
2026-08-21
Advisory published
2026-08-20
Advisory updated
2026-08-21

Who should care

Organizations using Frappe framework versions prior to 15.115.0 or 16.27.0 should be aware of this vulnerability and take steps to mitigate it. Security teams and administrators responsible for web application security should prioritize patching and monitoring for potential exploitation attempts.

Technical summary

The Frappe framework, prior to versions 15.115.0 and 16.27.0, has a vulnerability that allows remote attackers to enumerate registered users. This is due to distinguishable response shapes for registered and unregistered email addresses in the public request-data web form and PersonalDataDownloadRequest class. The issue is fixed in versions 15.115.0 and 16.27.0. To mitigate this vulnerability, it is essential to update to the patched versions and monitor for potential exploitation attempts. The vulnerability's CVSS score of 6.9 indicates a medium-priority risk, emphasizing the need for prompt action to protect against user enumeration attacks. Evidence from official CVE and NVD records confirms the vulnerability's existence and provides details on the affected versions and patches. Security teams and administrators responsible for web application security should prioritize patching and monitoring for potential exploitation attempts. Additional security measures, such as implementing rate limiting and monitoring for suspicious activity, can help protect against enumeration attacks. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their systems from potential exploitation. It is also crucial to verify the integrity of the Frappe framework and ensure that all instances are running with the latest security patches. Regular security audits and penetration testing can help identify potential vulnerabilities and ensure the overall security posture of the organization. By staying informed and proactive, organizations can minimize the risk of exploitation and maintain the security of their systems. The CVE record and NVD entry provide details on the vulnerability in Frappe, a full-stack web application framework. The issue allows remote attackers to enumerate registered users by comparing responses from the public request-data web form and PersonalDataDownloadRequest class. Evidence is based on official CVE and NVD records, as well as source references from [email protected]. The vulnerability's impact can be mitigated by applying patches or updates to versions 15.115.0 or 16.27.0, or later, and by and

Defensive priority

Medium-priority defensive tasks are recommended given the CVSS score of 6.9 and the potential for user enumeration.

Recommended defensive actions

  • Inventory and verify Frappe framework versions to identify potential exposure
  • Apply patches or updates to versions 15.115.0 or 16.27.0, or later
  • Monitor for suspicious activity related to user enumeration attempts
  • Consider implementing additional security measures to protect against enumeration attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Frappe, a full-stack web application framework. The issue allows remote attackers to enumerate registered users by comparing responses from the public request-data web form and PersonalDataDownloadRequest class. Evidence is based on official CVE and NVD records, as well as source references from [email protected].

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T19:16:58.187Z and has not been modified since then.