Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe frappe |
|
| Vendors & Products |
Frappe
Frappe frappe |
Thu, 20 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in frappe/templates/includes/oauth_confirmation.html, and without scoping an active OAuth token check to the requesting client. An attacker can cause an authenticated user to approve an OAuth grant or reuse authorization state for the wrong client, exposing data and permitting actions within the granted scopes. This issue is fixed in versions 15.114.0 and 16.26.0. | |
| Title | Frappe: Improper Authorization in OAuth2 Consent Endpoint | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T18:27:32.056Z
Reserved: 2026-07-23T18:54:15.833Z
Link: CVE-2026-66001
No data.
Status : Received
Published: 2026-08-20T19:16:58.020
Modified: 2026-08-20T19:16:58.020
Link: CVE-2026-66001
No data.
OpenCVE Enrichment
Updated: 2026-08-20T19:30:05Z
-
CWE-352
Cross-Site Request Forgery (CSRF)