CVE-2026-44976: Frappe: IDOR in update_onboarding_step
Published Jun 12, 2026
·Updated
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.
Affected Software
1 affected component
Frappe frappe<16.17.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.17.4
Event History
Jun 12, 2026
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44976?
CVE-2026-44976 has a medium severity rating of 5.3 according to the CVSS score.
2
How do I fix CVE-2026-44976?
To fix CVE-2026-44976, update Frappe to version 16.17.4 or later.
3
What kind of vulnerability is CVE-2026-44976?
CVE-2026-44976 is an Insecure Direct Object Reference (IDOR) vulnerability in the update_onboarding_step functionality.
4
Who is affected by CVE-2026-44976?
Any user of Frappe prior to version 16.17.4 is potentially affected by CVE-2026-44976.
5
When was CVE-2026-44976 published?
CVE-2026-44976 was published on June 12, 2026.