XML External Entity Vulnerability in ERPNext by Frappe
CVE-2026-44445
5.3MEDIUM
What is CVE-2026-44445?
ERPNext, an open-source Enterprise Resource Planning tool, exhibits an XML External Entity (XXE) vulnerability in its EDI Module. This vulnerability allows an authenticated attacker to exploit improper restrictions, potentially leading to unauthorized access to sensitive local files, including configuration files. This critical issue has been addressed in versions 15.104.3 and 16.12.0, emphasizing the need for users to update to the latest release to safeguard their systems.
Affected Version(s)
erpnext >= 16.0.0-beta.1, < 16.12.0 < 16.0.0-beta.1, 16.12.0
erpnext < 15.104.3 < 15.104.3
