---
id: CVE-2026-66000
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 16.23.0 and
  15.112.0, Document Follow notification generation does not re-evaluate the
  recipient's current document permissions, allowing users whose access was
  revoked or reduce…
severity: none
cwe:
  - CWE-863
published: '2026-08-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66000'
references:
  - url: >-
      https://github.com/frappe/frappe/commit/0914acb998004b3878eb5cf57b765115305b49a6
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/frappe/commit/b02c1aec2c75eb0819cc6730dd230c2acb0fa60d
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-wcm9-vvcc-r8pr'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0045
epssPercentile: 0.3645
ingestedAt: '2026-09-08T21:11:12.272Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
