What is CVE-2026-66059?
A field-level permissions bypass vulnerability discovered in the Frappe full-stack web application framework (prior to versions 16.20.0 and 15.112.0) can expose restricted DocType fields. It is strongly recommended to upgrade to the fixed versions 16.23.0 and 15.112.0 to mitigate the risk.
Azərbaycanca: Frappe full-stack web tətbiq framework-ində aşkar edilən CVE-2026-66059 zəifliyi, sahə səviyyəli icazələrin (field-level permissions) bypass edilməsinə səbəb olur. Bu, 16.20.0 və 15.112.0 versiyalarından əvvəlki versiyalara təsir edir və məhdud DocType sahələrinin ifşa olunması ilə nəticələnə bilər; ən qısa zamanda 16.23.0 və 15.112.0 versiyalarına yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Frappe framework are affected by CVE-2026-66059?
This vulnerability affects versions prior to 16.20.0 and 15.112.0.
To which versions should users upgrade to mitigate CVE-2026-66059?
It is recommended to upgrade to versions 16.23.0 and 15.112.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.