Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 43 MIN AGO
T-43M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-66001
Frappe: Improper Authorization in OAuth2 Consent Endpoint
High
PUBLISHED
CNA: GitHub_M
Base score
8.5
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
View raw JSON
CVE Program record
02
Description
CNA: GitHub_M
Frappe: Improper Authorization in OAuth2 Consent Endpoint
03
Metadata
SCHEMA: 5.2
Published
2026-08-20 18:27Z
1 DAY AGO
Last updated
2026-08-20 18:27Z
1 DAY AGO
Reserved
2026-07-23
Assigning CNA
GitHub_M
Record state
PUBLISHED
Severity
High (CVSS 8.5)
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
Compound
SSVC decision
No CISA-ADP assessment
Data version
5.2
Document digest
1598dc558e1d8a179bbf03ea5b2cba60a5e3e887c8298b6afa6c75057d546829
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
frappe
frappe
< 15.114.0, >= 16.0.0-beta.1, < 16.26.0
—
05
References
REFS: 9
github.com
https://github.com/frappe/frappe/security/advisories/GHSA-2ph8-x773-8p2x
x_refsource_CONFIRM
github.com
https://github.com/frappe/frappe/pull/40073
x_refsource_MISC
github.com
https://github.com/frappe/frappe/pull/40700
x_refsource_MISC
github.com
https://github.com/frappe/frappe/pull/40701
x_refsource_MISC
github.com
https://github.com/frappe/frappe/commit/336c7d335db762b494acdfe43aea69d459fd51d7
x_refsource_MISC
github.com
https://github.com/frappe/frappe/commit/d7460769f999c68d3121b680119f8724ddd3eb9d
x_refsource_MISC
github.com
https://github.com/frappe/frappe/commit/eb9c1446cac13236c6d573b136786db2e46254fa
x_refsource_MISC
github.com
https://github.com/frappe/frappe/releases/tag/v15.114.0
x_refsource_MISC
github.com
https://github.com/frappe/frappe/releases/tag/v16.26.0
x_refsource_MISC