CVE-2026-72909
ERPNext: Broken Access Control on certain endpoints
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field, allowing any authenticated user to read unauthorized cross-company financial data in Accounts Receivable and Accounts Payable reports. This issue is fixed in versions 15.112.0 and 16.23.0.
| CWE | CWE-284 |
| Vendor | frappe |
| Product | erpnext |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for frappe erpnext
Be the first to know when new unknown vulnerabilities affecting frappe erpnext are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
frappe / erpnext
< 15.112.0 >= 16.0.0, < 16.23.0
References
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-p577-cxv9-h82f github.com: https://github.com/frappe/erpnext/pull/55696 github.com: https://github.com/frappe/erpnext/commit/b05abbc53b3655b02db17ba2e8165519f195c1c2 github.com: https://github.com/frappe/erpnext/commit/c03a66a1bf48a53c42d01c9d936d9b22aa013e11 github.com: https://github.com/frappe/erpnext/releases/tag/v15.112.0 github.com: https://github.com/frappe/erpnext/releases/tag/v16.23.0