Unauthorized Method Invocation in Frappe ERPNext by Frappe
CVE-2026-96672
5.3MEDIUM
What is CVE-2026-96672?
Frappe ERPNext versions prior to 16.34.1 include a vulnerability where the Financial Report Template fails to validate the calculation_formula values. This allows accounts managers to provide arbitrary dotted Python paths, resulting in the invocation of internal server-side methods that are not whitelisted. Consequently, unauthorized reading of return values from these methods could expose sensitive data, posing a significant security risk.
Affected Version(s)
ERPNext 16.0.0 < 16.34.1
