Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-66003— Frappe: Access control bypass via REST API dot-notation fields on linked doctypes

Quick assessment

Affected
frappe frappe
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Frappe 是一个使用 Python 和 JavaScript 编写的全栈 Web 应用框架。在版本 15.115.0 之前,其 REST API 中存在访问控制绕过漏洞,允许用户读取来自关联 DocType(文档类型)的数据,而这些数据原本不在其授权访问范围内。当某个文档通过 Link 字段引用另一个文档时,框架在通过 REST API 获取记录时,未能一致地强制应用被关联 DocType 自身的权限规则,导致低权限的已认证用户可以获取其权限范围之外的关联记录字段。该问题已在版本 15.115.0 中修复。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66003

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Frappe: Access control bypass via REST API dot-notation fields on linked doctypes
Source: CVE Program / CVE List V5
Vulnerability Description
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another document through a Link field, the framework does not consistently enforce the linked DocType's own permissions when the record is retrieved through the REST API, so a low-privileged authenticated user can obtain fields from linked records outside their permitted scope. This issue is fixed in version 15.115.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
frappe frappe < 15.115.0 -

II. Public POCs for CVE-2026-66003

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7870 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-66003

登录查看更多情报信息。

Vendor Advisories for CVE-2026-66003 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-66003

No comments yet


Leave a comment