LOWVulnerability

CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

Properties

epss_score
0.00225
cve_id
CVE-2026-66058
published_at
2026-08-07T18:17:20.953
last_modified
2026-09-08T20:51:43.490
epss_percentile
0.13118

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Authorization Bypass Through User-Controlled Key
[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66058 — Ninja Signal Threat Intelligence | Ninja Signal