CVE-2026-58503: Frappe

Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

Affected products

  • Frappe Frappe: before 15.106.0 (fixed in 15.106.0); from 16.0.0-beta1, before 16.16.0 (fixed in 16.16.0)

Published 2026-07-10. Last modified 2026-07-13.