Permission Management Flaw in ERPNext Affects Data Security
CVE-2026-72910
7.1HIGH
What is CVE-2026-72910?
ERPNext, an open-source ERP solution, has a significant vulnerability that allows authenticated limited users to modify sensitive data outside of their assigned roles. This flaw exists in multiple functions across various Python files, where crucial write permission checks have been omitted. Users may exploit this vulnerability to make unauthorized changes. The issue has been addressed in versions 15.112.0 and 16.22.0, highlighting the importance of updating to ensure comprehensive access control.
Affected Version(s)
erpnext < 15.112.0 < 15.112.0
erpnext >= 16.0.0, < 16.22.0 < 16.0.0, 16.22.0
