Authorization Bypass in ERPNext by Frappe
CVE-2026-44442
9.9CRITICAL
What is CVE-2026-44442?
ERPNext, a widely-used open-source Enterprise Resource Planning tool, was found to possess a vulnerability that allowed users to circumvent authorization checks on certain endpoints. This flaw enabled unauthorized data modifications beyond the scope of a user's assigned role. Frappe has addressed this issue in version 16.9.1, ensuring that proper authorization checks are enforced to maintain the integrity and security of user data.
Affected Version(s)
erpnext < 16.9.1
