PT-2026-48894 · Frappe · Frappe

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-44976

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-44976

Affected Products

Frappe