Authorization Bypass in ERPNext Affects Accounting Data Integrity
CVE-2026-72907

6.5MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72907?

ERPNext, an open-source Enterprise Resource Planning tool, contains a significant vulnerability where the add_ac function in erpnext/accounts/utils.py permits the ignore_permissions argument without proper checks. This oversight allows an authenticated but limited user to create unauthorized accounting master records, compromising financial data integrity and audit trails. Users are strongly advised to upgrade to versions 15.111.0 and 16.22.0 to mitigate these risks effectively.

Affected Version(s)

erpnext < 15.111.0 < 15.111.0

erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.