Home

Description

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

PUBLISHED Reserved 2026-05-05 | Published 2026-06-12 | Updated 2026-06-12 | Assigner GitHub_M




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639: Authorization Bypass Through User-Controlled Key

Product status

< 15.107.0
affected

< 16.17.0
affected

References

github.com/...frappe/security/advisories/GHSA-cw6v-39qx-7r74

cve.org (CVE-2026-44207)

nvd.nist.gov (CVE-2026-44207)

Download JSON