Nested Cancellation Vulnerability in Pacioli for ERPNext by John Broadway
CVE-2026-107841
5.7MEDIUM
What is CVE-2026-107841?
The Pacioli platform, which supports governance in ERPNext, contains a vulnerability in the document-layer consent gate feature. Specifically, from versions 0.9.6 to 0.10.0, it allows unauthorized cancellation of documents by bypassing necessary consent checks. Users with specific credential scopes can manipulate the submission of a Sales Invoice or other documents, resulting in the ability to cancel transactions that they should not have permission to affect. This can lead to significant financial discrepancies as unauthorized cancellations can reverse ledger effects without proper authorization. The issue has been resolved in version 0.10.0.
Affected Version(s)
pacioli >= 0.9.6, < 0.10.0
