CVE-2026-66059EPSS p39.0%

CVE-2026-66059CVE-2026-66059

Description

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

Scoring

EPSS0.48% probability of exploitation · percentile 39.0% · 2026-10-05T12:00:23Z
Last modified2026-09-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.