PT-2026-48890 · Frappe · Frappe

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-44207

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-44207

Affected Products

Frappe