← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 20, 2026 · 18:29via CVEFeed

CVE-2026-66002 - Frappe: User Enumeration via PDDR

Brief

CVE ID : CVE-2026-66002

Published : Aug. 20, 2026, 6:29 p. m.

  • 40 minutes ago

Description : Frappe is a full-stack web application framework. Prior to 15.

  • 0 and 16.
  • 0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request. py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior.

A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.

  • 0 and 16.
  • 0.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed