CVE-2026-66002 | Frappe up to 15.114.x/16.26.x personal_data_download_request.py PersonalDataDownloadRequest information disclosure

SecurityVulns

A vulnerability described as problematic has been identified in Frappe up to 15.114.x/16.26.x. Affected is the function PersonalDataDownloadRequest of the file frappe/website/doctype/personal_data_download_request/personal_data_download_request.py. Executing a manipulation can lead to information disclosure.

This vulnerability is tracked as CVE-2026-66002. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More