CVE-2026-44976EPSS p19.3%

CVE-2026-44976CVE-2026-44976

Description

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

Scoring

EPSS0.28% probability of exploitation · percentile 19.3% · 2026-06-19T12:03:05Z
Last modified2026-06-12
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.