๐Ÿ” CVE Alert

CVE-2026-107841

MEDIUM 5.7

pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.

CWE CWE-863
Vendor john-broadway
Product pacioli
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for john-broadway pacioli

Be the first to know when new medium vulnerabilities affecting john-broadway pacioli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

john-broadway / pacioli
>= 0.9.6, < 0.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/john-broadway/pacioli/security/advisories/GHSA-3hj7-6vmj-h8v4 github.com: https://github.com/john-broadway/pacioli/commit/f3c7219f5dde6050bd7921e0ac55afd02771250c github.com: https://github.com/john-broadway/pacioli/releases/tag/guard-v0.10.0