Server-side Template Injection Vulnerability in ERPNext by Frappe
CVE-2026-65974

9.9CRITICAL

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-65974?

ERPNext, an open source Enterprise Resource Planning tool, is exposed to a significant security flaw that allows limited authenticated users to bypass permission boundaries. This is due to the exposure of the 'frappe.render_template' function without adequate restrictions on globals, which can lead to server-side template injection vulnerabilities. This security concern can potentially allow attackers to execute arbitrary code remotely. The issue has been resolved in versions 15.111.0 and 16.22.0. It is crucial for users running affected versions to upgrade to ensure the integrity and security of their systems.

Affected Version(s)

erpnext < 15.111.0 < 15.111.0

erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.