Junglewise Threat Intelligence

CVE-2026-44206: Frappe Framework DB schema enumeration via endpoint

CVE-2026-44206 · Severity: info · CVSS 6.9 · Published 2026-06-12

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe, a web application framework, contains a vulnerability that allows unauthorized users to discover the internal structure of its database. By exploiting a specific web endpoint, an attacker can map out how data is organized, which is often a precursor to more advanced attacks like data theft. This issue has been resolved in the latest software updates.

Technical details

A vulnerability in Frappe Framework (prior to versions 15.107.2 and 16.17.4) allows for database schema enumeration. The flaw exists in a specific web endpoint that fails to properly restrict access or sanitize requests, enabling an unauthenticated remote attacker to gather information about the database structure (CWE-200). This information disclosure can be used to facilitate further targeted attacks against the application's data layer. The issue is addressed in versions 15.107.2 and 16.17.4.

Affected products

  • Frappe Frappe Framework < 15.107.2, < 16.17.4

Timeline

  • 2026-06-03: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References

Related threats