Junglewise Threat Intelligence

CVE-2026-58503: Frappe Framework user enumeration in reset_password endpoint

CVE-2026-58503 · Severity: info · CVSS 6.9 · Published 2026-07-10

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies.

Executive brief

Frappe is a web application framework used to build business software like ERPNext. A flaw in the password reset feature allowed unauthorized individuals to determine if specific email addresses were registered users of the system. This type of information can be used to facilitate targeted phishing or brute-force attacks against your employees or customers.

Technical details

A user enumeration vulnerability exists in Frappe Framework's reset_password endpoint due to an observable discrepancy (CWE-203). Prior to the fix, the application returned different responses or confirmation messages depending on whether the submitted email address existed in the database. An unauthenticated remote attacker could exploit this by submitting a list of email addresses and observing the responses to identify valid accounts. The fix ensures that the application returns a consistent confirmation message regardless of whether the email address is registered. This has been patched in versions 15.106.0 and 16.16.0.

Affected products

  • Frappe Technologies Frappe Framework < 15.106.0, >= 16.0.0-beta1, < 16.16.0

Timeline

  • 2026-04-15: other: Fixes developed and backported in GitHub pull requests
  • 2026-04-21: patched: Versions 15.106.0 and 16.16.0 released
  • 2026-07-10: disclosed: CVE-2026-58503 published

References

Related threats