Arbitrary Code Execution Risk in ERPNext by Frappe
CVE-2026-72911
9.9CRITICAL
What is CVE-2026-72911?
ERPNext, an open-source Enterprise Resource Planning tool by Frappe, contains a vulnerability in its template rendering functions that permits authenticated users with common operational roles to inject arbitrary template expressions. This flaw arises from the handling of subject, body, and pdf_name fields in process_statement_of_accounts.py, enabling the execution of server-side code and unauthorized data access within the application. The issue has been addressed in versions 15.118.0 and 16.29.0, which restrict the use of globals during template validation.
Affected Version(s)
erpnext < 15.118.0 < 15.118.0
erpnext >= 16.0.0, < 16.29.0 < 16.0.0, 16.29.0
