Executive brief
Frappe is a web application framework used to build business software. A security flaw allows any logged-in user to reset the onboarding process and introductory tours for every other user in the system. While this does not expose sensitive data, it can disrupt the user experience and interfere with standard business workflows across the organization.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Frappe framework's onboarding and form tour components. The root cause is an insufficient permission check that allows any authenticated user, regardless of their privilege level, to trigger a reset of onboarding tours for the entire user base. The attack is reachable over the network and requires only basic user authentication. An attacker can exploit this to cause minor operational disruption by forcing all users to re-encounter introductory walkthroughs. The issue is resolved in versions 15.107.2 and 16.17.4.
Affected products
- Frappe Technologies Frappe < 15.107.2, < 16.17.4
Timeline
- 2026-06-07: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD