๐Ÿ” CVE Alert

CVE-2026-96672

MEDIUM 6.4

Frappe ERPNext before 16.34.1 Unauthorized Method Invocation

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.

CWE CWE-470
Vendor frappe
Product erpnext
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for frappe erpnext

Be the first to know when new medium vulnerabilities affecting frappe erpnext are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Frappe / ERPNext
16.0.0 < 16.34.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frappe/erpnext/security/advisories/GHSA-794x-fhm7-58j7 github.com: https://github.com/frappe/erpnext/commit/7aad59b129711e9bba17b25665428d1fc57bf37c github.com: https://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_engine.py#L1166-L1171 github.com: https://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_template.json github.com: https://github.com/frappe/erpnext vulncheck.com: https://www.vulncheck.com/advisories/frappe-erpnext-before-16.34.1-unauthorized-method-invocation

Credits

SRTSubmersionAI