Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in frappe/templates/includes/oauth_confirmation.html, and without scoping an active OAuth token check to the requesting client. An attacker can cause an authenticated user to approve an OAuth grant or reuse authorization state for the wrong client, exposing data and permitting actions within the granted scopes. This issue is fixed in versions 15.114.0 and 16.26.0.
CVE-2026-66001
This high-severity CVE scores 8.5 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.2%, top 86% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.5
- EG Score
- 8.5(medium)
- EG Risk
- 38(Track)EG Risk 38/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity85% × 45%Exploitation0% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 14%
- KEV
- Not listed
Published
August 20, 2026
Last Modified
August 25, 2026
Advisory Details (9)
Auto-updated Aug 20, 2026v16.26.0
Patch available: frappe/frappe v16.26.0
https://github.com/frappe/frappe/releases/tag/v16.26.0v15.114.0
Patch available: frappe/frappe v15.114.0
https://github.com/frappe/frappe/releases/tag/v15.114.0commit eb9c1446cac1 (frappe/frappe)
Patch available: frappe/frappe v16.26.0 (contains commit eb9c1446cac1)
https://github.com/frappe/frappe/commit/eb9c1446cac13236c6d573b136786db2e46254facommit d7460769f999 (frappe/frappe)
Patch available: frappe/frappe v15.114.0 (contains commit d7460769f999)
https://github.com/frappe/frappe/commit/d7460769f999c68d3121b680119f8724ddd3eb9dcommit 336c7d335db7 (frappe/frappe)
Fix landed in frappe/frappe commit 336c7d335db7 — awaiting tagged release
https://github.com/frappe/frappe/commit/336c7d335db762b494acdfe43aea69d459fd51d7fix: hardening oauth endpoints (backport #40073)
Patch available: frappe/frappe v15.114.0 (PR #40701 merged 2026-07-09)
https://github.com/frappe/frappe/pull/40701fix: hardening oauth endpoints (backport #40073)
Patch available: frappe/frappe v16.26.0 (PR #40700 merged 2026-07-09)
https://github.com/frappe/frappe/pull/40700fix: hardening oauth endpoints
Fix merged in frappe/frappe PR #40073 on 2026-07-09 — awaiting tagged release
https://github.com/frappe/frappe/pull/40073Improper Authorization in OAuth2 Consent Endpoint · Advisory · frappe/frappe · GitHub
https://github.com/frappe/frappe/security/advisories/GHSA-2ph8-x773-8p2xWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 13× in last 7d / 19× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-30 02:44 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 01:28 UTCEG score recompute
- 2026-08-28 21:42 UTCEPSS rescore
- 2026-08-27 19:18 UTCEG score recompute
- 2026-08-26 17:53 UTCEG score recompute
- 2026-08-26 14:47 UTCEPSS rescore
- 2026-08-25 16:26 UTCEG score recompute
- 2026-08-25 15:31 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 00:00 UTCEG score recompute
- 2026-08-24 11:25 UTCEG score recompute
- 2026-08-23 10:16 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 09:02 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-20 19:18 UTCEG score recompute
- 2026-08-20 18:32 UTCEG score recompute
- 2026-08-20 18:31 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-66001?
When was CVE-2026-66001 disclosed?
Is CVE-2026-66001 actively exploited?
What is the CVSS score of CVE-2026-66001?
How do I remediate CVE-2026-66001?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-66001
Is Your Infrastructure Affected by CVE-2026-66001?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.