User Enumeration Vulnerability in Frappe Framework
CVE-2026-58503

6.9MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
10 July 2026

What is CVE-2026-58503?

The Frappe Framework, a full-stack web application framework, was found to have a vulnerability that allowed for user enumeration through the reset_password endpoint. Attackers could potentially exploit this weakness to determine valid usernames. This issue has been addressed and fixed in versions 16.16.0 and 15.106.0, improving the security posture of applications that rely on the Frappe Framework.

Affected Version(s)

frappe < 15.106.0 < 15.106.0

frappe >= 16.0.0-beta1, < 16.16.0 < 16.0.0-beta1, 16.16.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.