๐Ÿ” CVE Alert

CVE-2026-72906

MEDIUM 4.3

ERPNext: Unauthorised triggering of automated emails due to missing validation

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails outside the permitted role. This issue is fixed in versions 15.111.0 and 16.22.0.

CWE CWE-862
Vendor frappe
Product erpnext
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for frappe erpnext

Be the first to know when new medium vulnerabilities affecting frappe erpnext are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

frappe / erpnext
< 15.111.0 >= 16.0.0, < 16.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-3x6c-gc4v-f5v8 github.com: https://github.com/frappe/erpnext/pull/55781 github.com: https://github.com/frappe/erpnext/commit/18ca96c36ba65362bf1c25abb8eab32c64c6c7dd github.com: https://github.com/frappe/erpnext/commit/e15879acd118ccd343e31ad3b5a6279e514c82c2 github.com: https://github.com/frappe/erpnext/releases/tag/v15.111.0 github.com: https://github.com/frappe/erpnext/releases/tag/v16.22.0