What is CVE-2026-66058?
An unrestricted access vulnerability was found in the Document Follow API (update_follow) of the Frappe framework for authenticated users. This could allow unauthorized operations. Upgrading to versions 16.20.0 or 15.112.0 is recommended to fix the issue.
Azərbaycanca: Frappe framework-də autentifikasiya olunmuş istifadəçilər üçün Document Follow API-də (update_follow) məhdudiyyətsiz giriş zəifliyi aşkar edilib. Bu, icazəsiz əməliyyatlara yol aça bilər. Problemi aradan qaldırmaq üçün 16.20.0 və ya 15.112.0 versiyalarına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which API of the Frappe framework was CVE-2026-66058 discovered?
This vulnerability was discovered in the Document Follow API, specifically in the update_follow function.
Which versions are recommended to upgrade to in order to fix CVE-2026-66058?
It is recommended to upgrade the Frappe framework to versions 16.20.0 or 15.112.0 to resolve the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.