CVE 5.3 MEDIUM

Frappe: IDOR in update_onboarding_step_CVE-2026-44976

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

Basic Information

ID CVE-2026-44976
Source GitHub_M
Published Jun 12, 2026 at 14:38

Affected Product

Vendor frappe
Product frappe
Version < 16.17.4
Affected Versions frappe frappe < 16.17.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.