๐Ÿ” CVE Alert

CVE-2026-72908

MEDIUM 6.5

ERPNext: Possibility of SQL injection due to missing validation

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject SQL and extract sensitive information. This issue is fixed in versions 15.109.0 and 16.20.0.

CWE CWE-89
Vendor frappe
Product erpnext
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for frappe erpnext

Be the first to know when new medium vulnerabilities affecting frappe erpnext are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

frappe / erpnext
< 15.109.0 >= 16.0.0, < 16.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-grhp-m55m-63f8 github.com: https://github.com/frappe/erpnext/pull/55127 github.com: https://github.com/frappe/erpnext/commit/2a91c7229a47ac6a5bb2d8227290b03415bf8baf github.com: https://github.com/frappe/erpnext/commit/c45d2a348777a9bdf697832b6ca129d2f0626fd2 github.com: https://github.com/frappe/erpnext/commit/f98975f51a62d611f536368671c3dbaf81d61eb9 github.com: https://github.com/frappe/erpnext/releases/tag/v15.109.0 github.com: https://github.com/frappe/erpnext/releases/tag/v16.20.0