Permission Check Bypass in ERPNext Affects Automated Email Functionality
CVE-2026-72906
4.3MEDIUM
What is CVE-2026-72906?
ERPNext, a widely-used open-source Enterprise Resource Planning tool, has a vulnerability in its send_auto_email function. Prior to versions 15.111.0 and 16.22.0, this function does not adequately check for permissions associated with the Process Statement Of Accounts. As a result, an authenticated user with low privileges can trigger automated emails, circumventing role restrictions. This flaw can lead to unauthorized email notifications and potentially expose sensitive information. The issue has been addressed in the updated versions, and users are strongly advised to upgrade to secure their instances.
Affected Version(s)
erpnext < 15.111.0 < 15.111.0
erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0
