Junglewise Threat Intelligence

CVE-2026-44207: Frappe Framework IDOR in email configuration

CVE-2026-44207 · Severity: info · CVSS 6.9 · Published 2026-06-12

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe is a web application framework used to build business software. A security flaw allows logged-in users to view the private email configuration details of other users on the system. This could lead to the exposure of sensitive communication settings and potentially impact user privacy.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Frappe Framework due to insufficient authorization checks on email account objects. By manipulating identifiers in requests, an authenticated attacker can bypass intended access controls to retrieve email configuration details belonging to other users (CWE-639). The vulnerability is reachable over the network and requires authentication but no user interaction. The issue has been addressed in versions 15.107.0 and 16.17.0.

Affected products

  • Frappe Frappe Framework < 15.107.0, < 16.17.0

Timeline

  • 2026-06-01: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References

Related threats