๐Ÿ” CVE Alert

CVE-2026-72910

HIGH 7.1

ERPNext: Unauthorised modification of master data due to missing validation

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py, erpnext/accounts/doctype/process_payment_reconciliation/process_payment_reconciliation.py, erpnext/accounts/doctype/purchase_invoice/purchase_invoice.py, and erpnext/accounts/utils.py omit required write permission checks, allowing authenticated limited users to modify protected data beyond their roles. This issue is fixed in versions 15.112.0 and 16.22.0.

CWE CWE-862
Vendor frappe
Product erpnext
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for frappe erpnext

Be the first to know when new high vulnerabilities affecting frappe erpnext are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

frappe / erpnext
< 15.112.0 >= 16.0.0, < 16.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-qpvh-75wh-j645 github.com: https://github.com/frappe/erpnext/pull/55709 github.com: https://github.com/frappe/erpnext/commit/2ae6451f10926bd12b6ce6c7dc40f08da83f2460 github.com: https://github.com/frappe/erpnext/commit/8c7a313a38dfe38c9e35ca41e91389bcfaed2404 github.com: https://github.com/frappe/erpnext/commit/ba936eefabb784805daa4c602b4baec9fc243ff8 github.com: https://github.com/frappe/erpnext/releases/tag/v15.112.0 github.com: https://github.com/frappe/erpnext/releases/tag/v16.22.0