CVE-2026-66058

Summary

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

Affected Software

VendorProductVersion RangeStatus
frappefrappe>= 16.0.0-beta.1, < 16.20.0affected
frappefrappe< 15.112.0affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization
  • CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key

References