Authorization Bypass in ERPNext Affects Accounting Data Integrity
CVE-2026-72907
6.5MEDIUM
What is CVE-2026-72907?
ERPNext, an open-source Enterprise Resource Planning tool, contains a significant vulnerability where the add_ac function in erpnext/accounts/utils.py permits the ignore_permissions argument without proper checks. This oversight allows an authenticated but limited user to create unauthorized accounting master records, compromising financial data integrity and audit trails. Users are strongly advised to upgrade to versions 15.111.0 and 16.22.0 to mitigate these risks effectively.
Affected Version(s)
erpnext < 15.111.0 < 15.111.0
erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0
