CVE 6.9 MEDIUM

Frappe: DB Schema Enumeration via Frappe-Authorization-Source_CVE-2026-44206

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

Basic Information

ID CVE-2026-44206
Source GitHub_M
Published Jun 12, 2026 at 14:34

Affected Product

Vendor frappe
Product frappe
Version < 15.107.2
Affected Versions frappe frappe < 15.107.2
frappe frappe < 16.17.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.