What is CVE-2026-66000?
A vulnerability exists in the Document Follow notification feature of the Frappe framework, where revoked user permissions are not re-evaluated, allowing former users to continue receiving document data via email. This affects Frappe versions prior to 16.23.0 and 15.112.0. Immediate update to the patched versions is recommended.
Azərbaycanca: Sənəd izləmə (Document Follow) bildiriş funksiyasında zəiflik aşkarlanıb: giriş icazələri ləğv edilmiş istifadəçilər email ilə sənəd məlumatlarını almağa davam edə bilər. Bu, "Frappe" framework-ün 16.23.0 və 15.112.0-dən əvvəlki versiyalarına təsir edir. Təcili olaraq göstərilən versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which users are affected by this vulnerability?
Former users whose permissions have been revoked can continue receiving document data via email through the 'Document Follow' notification feature.
Which versions should be updated to?
Immediate update to Frappe framework versions 16.23.0 or 15.112.0 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.