Frappe · Frappe · CVE-2026-66003
**Name of the Vulnerable Software and Affected Versions**
Frappe versions prior to 15.115.0
**Description**
An access control bypass exists in the REST API of the Frappe framework. When a document references another document via a Link field, the system fails to consistently enforce the permissions of the linked DocType during record retrieval. This allows a low-privileged authenticated user to read data and obtain fields from linked records that are outside their authorized scope.
**Recommendations**
Update to version 15.115.0.