Server-side Template Injection Vulnerability in ERPNext by Frappe
CVE-2026-65974
9.9CRITICAL
What is CVE-2026-65974?
ERPNext, an open source Enterprise Resource Planning tool, is exposed to a significant security flaw that allows limited authenticated users to bypass permission boundaries. This is due to the exposure of the 'frappe.render_template' function without adequate restrictions on globals, which can lead to server-side template injection vulnerabilities. This security concern can potentially allow attackers to execute arbitrary code remotely. The issue has been resolved in versions 15.111.0 and 16.22.0. It is crucial for users running affected versions to upgrade to ensure the integrity and security of their systems.
Affected Version(s)
erpnext < 15.111.0 < 15.111.0
erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0
