CVE 5.3 MEDIUM

Frappe: Missing authorization on reset form tours_CVE-2026-44975

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

Basic Information

ID CVE-2026-44975
Source GitHub_M
Published Jun 12, 2026 at 14:35

Affected Product

Vendor frappe
Product frappe
Version < 15.107.2
Affected Versions frappe frappe < 15.107.2
frappe frappe < 16.17.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.