LOWVulnerability

CVE-2026-66059

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

Properties

epss_score
0.00275
cve_id
CVE-2026-66059
published_at
2026-08-07T16:17:26.513
last_modified
2026-09-08T20:51:43.490
epss_percentile
0.19584

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66059 — Ninja Signal Threat Intelligence | Ninja Signal