CVE-2026-44975
Last modified
CVE-2026-44975 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-44975?
How severe is CVE-2026-44975?
How do I fix CVE-2026-44975?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4497A vulnerability was determined in Totolink WA300 5.2cu.7112_…9.8
- CVE-2026-44970dbt-mcp is a Model Context Protocol server for interacting w…4.3
- CVE-2026-44971GuardDog is a CLI tool to identify malicious PyPI packages. …8.2
- CVE-2026-44972GuardDog is a CLI tool to identify malicious PyPI packages. …5
- CVE-2026-44973Billy is an interface filesystem abstraction for Go. Prior t…8.1
- CVE-2026-44974@hapi/content provided HTTP Content-* headers parsing. Prior…7.7
- CVE-2026-44976Frappe is a full-stack web application framework. Prior to v…5.3
- CVE-2026-44978xrdp is an open source RDP server. Versions 0.10.6 and prior…5.3
- CVE-2026-44979@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when…6.3
- CVE-2026-4498Execution with Unnecessary Privileges (CWE-250) in Kibana’s …7.7
- CVE-2026-44981CrowdSec offers crowdsourced protection against malicious IP…8.2
- CVE-2026-44982CrowdSec offers crowdsourced protection against malicious IP…7.2
Are you affected by CVE-2026-44975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
