SQL Injection Vulnerability in ERPNext Affects Sales Reports
CVE-2026-65822
7.6HIGH
What is CVE-2026-65822?
Prior to versions 15.116.0 and 16.23.0, ERPNext contains a security flaw in the 'inactive_customers.py' script, where it accepts an unvalidated doctype filter, allowing authenticated users to manipulate raw SQL queries. This could lead to unauthorized data extraction, compromising sensitive customer information and potentially manipulating database queries. The vulnerability has been remediated in the specified updates, emphasizing the importance of timely software patches.
Affected Version(s)
erpnext < 15.116.0 < 15.116.0
erpnext >= 16.0.0, < 16.23.0 < 16.0.0, 16.23.0
