CVE-2026-107841
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.
| CWE | CWE-863 |
| Vendor | john-broadway |
| Product | pacioli |
| Published | Oct 9, 2026 |
| Last Updated | Oct 9, 2026 |
Get instant alerts for john-broadway pacioli
Be the first to know when new medium vulnerabilities affecting john-broadway pacioli are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N