CVE-2026-58503EPSS p46.3%
CVE-2026-58503CVE-2026-58503
Description
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.
Scoring
| EPSS | 0.59% probability of exploitation · percentile 46.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |