Permission Check Bypass in ERPNext Affects Automated Email Functionality
CVE-2026-72906

4.3MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72906?

ERPNext, a widely-used open-source Enterprise Resource Planning tool, has a vulnerability in its send_auto_email function. Prior to versions 15.111.0 and 16.22.0, this function does not adequately check for permissions associated with the Process Statement Of Accounts. As a result, an authenticated user with low privileges can trigger automated emails, circumventing role restrictions. This flaw can lead to unauthorized email notifications and potentially expose sensitive information. The issue has been addressed in the updated versions, and users are strongly advised to upgrade to secure their instances.

Affected Version(s)

erpnext < 15.111.0 < 15.111.0

erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.