CVE-2026-44975: Frappe: Missing authorization on reset form tours
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.107.2 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.17.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44975?
The severity of CVE-2026-44975 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-44975?
CVE-2026-44975 can be fixed by upgrading to Frappe versions 15.107.2 or 16.17.4.
What impact does CVE-2026-44975 have on my system?
CVE-2026-44975 allows any authenticated user to reset onboarding for all users, potentially disrupting user settings.
Is CVE-2026-44975 affecting all versions of Frappe?
Yes, CVE-2026-44975 affects all versions of Frappe prior to 15.107.2 and 16.17.4.
How can I identify if my Frappe installation is vulnerable to CVE-2026-44975?
You can identify vulnerability by checking if your Frappe version is earlier than 15.107.2 or 16.17.4.