---
id: CVE-2026-58503
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 16.16.0 and
  15.106.0, user enumeration could be performed via the reset_password endpoint.
  This issue is fixed in versions 16.16.0 and 15.106.0.
severity: none
cwe:
  - CWE-203
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58503'
references:
  - url: >-
      https://github.com/frappe/frappe/commit/1ff64d4a67f9a6d8819ac059dc69f023fb9ea264
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/frappe/commit/d3becf5672cbb5c7150447161941aeebeeb84ae8
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/38625'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/pull/38626'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/releases/tag/v15.106.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/releases/tag/v16.16.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-3vqc-c545-w7jg'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0059
epssPercentile: 0.46938
ingestedAt: '2026-07-11T22:16:00.725Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
