Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior. A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.115.0 and 16.27.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 19:16
Updated : 2026-09-10 20:48
NVD link : CVE-2026-66002
Mitre link : CVE-2026-66002
CVE.ORG link : CVE-2026-66002
JSON object : View
Products Affected
No product.
CWE
CWE-204
Observable Response Discrepancy
