Nested Cancellation Vulnerability in Pacioli for ERPNext by John Broadway
CVE-2026-107841

5.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107841?

The Pacioli platform, which supports governance in ERPNext, contains a vulnerability in the document-layer consent gate feature. Specifically, from versions 0.9.6 to 0.10.0, it allows unauthorized cancellation of documents by bypassing necessary consent checks. Users with specific credential scopes can manipulate the submission of a Sales Invoice or other documents, resulting in the ability to cancel transactions that they should not have permission to affect. This can lead to significant financial discrepancies as unauthorized cancellations can reverse ledger effects without proper authorization. The issue has been resolved in version 0.10.0.

Affected Version(s)

pacioli >= 0.9.6, < 0.10.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.