{"id":"CVE-2026-58503","title":"Frappe is a full-stack web application framework","summary":"Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.","severity":"none","cwe":["CWE-203"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58503","references":[{"url":"https://github.com/frappe/frappe/commit/1ff64d4a67f9a6d8819ac059dc69f023fb9ea264","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/commit/d3becf5672cbb5c7150447161941aeebeeb84ae8","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/pull/38625","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/pull/38626","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/releases/tag/v15.106.0","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/releases/tag/v16.16.0","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-3vqc-c545-w7jg","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.0059,"epssPercentile":0.46638,"ingestedAt":"2026-07-11T22:16:00.725Z","slug":"CVE-2026-58503","body":"## Overview\n\nFrappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}