Frappe: IDOR in update_onboarding_step
CVE-2026-44976
5.3MEDIUM
What is CVE-2026-44976?
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.
Affected Version(s)
frappe < 16.17.4
