CVE-2026-66002
CVE-2026-66002 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-204.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.9)
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-204
- Published:
- Last modified:
Description
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior. A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.115.0 and 16.27.0.
Frequently asked questions
- What is CVE-2026-66002?
- Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior. A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.115.0 and 16.27.0.
- How severe is CVE-2026-66002?
- CVE-2026-66002 has a CVSS 4.0 base score of 6.9, rated medium severity.
- Is CVE-2026-66002 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-66002?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-66002 published?
- CVE-2026-66002 was published on 2026-08-20 and last updated on 2026-08-21.
References
- https://github.com/frappe/frappe/commit/30fe0b4118ff94c95c239dce4bc74ec4ca10a827
- https://github.com/frappe/frappe/commit/47a396ec59f5362029feb349eb2b9d10a21afcf8
- https://github.com/frappe/frappe/commit/4b32a4e0072e61ce0abcb0d09cfd1f14724fe896
- https://github.com/frappe/frappe/pull/40787
- https://github.com/frappe/frappe/pull/40814
- https://github.com/frappe/frappe/pull/40815
- https://github.com/frappe/frappe/releases/tag/v15.115.0
- https://github.com/frappe/frappe/releases/tag/v16.27.0
- https://github.com/frappe/frappe/security/advisories/GHSA-c2xv-c53h-qvr5
Other CWE-204 vulnerabilities
- CVE-2018-25350 — Critical (CVSS 9.8): userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid…
- CVE-2026-15747 — Critical (CVSS 9.1): Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a…
- CVE-2026-69519 — High (CVSS 8.6): Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a…
- CVE-2025-5485 — High (CVSS 8.6): User names used to access the web management interface are limited to the device identifier, which is a numerical…
- CVE-2026-27462 — High (CVSS 7.5): Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for…
- CVE-2026-33419 — High (CVSS 7.5): MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security…