PT-2026-82278 · Frappe · Frappe

·

CVE-2026-66003

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 15.115.0
Description An access control bypass exists in the REST API of the Frappe framework. When a document references another document via a Link field, the system fails to consistently enforce the permissions of the linked DocType during record retrieval. This allows a low-privileged authenticated user to read data and obtain fields from linked records that are outside their authorized scope.
Recommendations Update to version 15.115.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66003
GHSA-P25M-7RVG-6FVR

Affected Products

Frappe