CVE-2026-58503: Frappe
Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.
Affected products
- Frappe Frappe: before 15.106.0 (fixed in 15.106.0); from 16.0.0-beta1, before 16.16.0 (fixed in 16.16.0)
Published 2026-07-10. Last modified 2026-07-13.