Remote Code Execution Risk in ERPNext by Frappe
CVE-2026-44441

5MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44441?

ERPNext, an open-source Enterprise Resource Planning tool by Frappe, is susceptible to a potential remote code execution vulnerability. Malicious actors can exploit this vulnerability by sending specially crafted requests to specific endpoints, causing the server to initiate unauthorized HTTP calls to external services defined by the attacker. This flaw affects all versions before 15.106.0 and 16.16.0, which have been patched to eliminate this security risk. Users are advised to update to fixed versions immediately to safeguard against potential exploits.

Affected Version(s)

erpnext < 15.106.0 < 15.106.0

erpnext >= 16.0.0-beta.1, < 16.16.0 < 16.0.0-beta.1, 16.16.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.