Arbitrary Code Execution Risk in ERPNext by Frappe
CVE-2026-72911

9.9CRITICAL

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72911?

ERPNext, an open-source Enterprise Resource Planning tool by Frappe, contains a vulnerability in its template rendering functions that permits authenticated users with common operational roles to inject arbitrary template expressions. This flaw arises from the handling of subject, body, and pdf_name fields in process_statement_of_accounts.py, enabling the execution of server-side code and unauthorized data access within the application. The issue has been addressed in versions 15.118.0 and 16.29.0, which restrict the use of globals during template validation.

Affected Version(s)

erpnext < 15.118.0 < 15.118.0

erpnext >= 16.0.0, < 16.29.0 < 16.0.0, 16.29.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.