---
id: CVE-2026-66002
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 15.115.0 and
  16.27.0, the public request-data web form and PersonalDataDownloadRequest
  class in
  frappe/website/doctype/personal_data_download_request/personal_data_download_reque…
severity: none
cwe:
  - CWE-204
published: '2026-08-20'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:48:30.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66002'
references:
  - url: >-
      https://github.com/frappe/frappe/commit/30fe0b4118ff94c95c239dce4bc74ec4ca10a827
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/frappe/commit/47a396ec59f5362029feb349eb2b9d10a21afcf8
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/frappe/commit/4b32a4e0072e61ce0abcb0d09cfd1f14724fe896
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/40787'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/40814'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/40815'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/releases/tag/v15.115.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/releases/tag/v16.27.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-c2xv-c53h-qvr5'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00468
epssPercentile: 0.39701
ingestedAt: '2026-09-10T21:05:53.597Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior. A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.115.0 and 16.27.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
