SB2026081380 - Multiple vulnerabilities in ERPNext



SB2026081380 - Multiple vulnerabilities in ERPNext

Published: August 13, 2026 Updated: August 15, 2026

Security Bulletin ID SB2026081380
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 29% Low 71%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify inventory records.

The vulnerability exists due to missing authorization in certain endpoints when handling requests. A remote user can send crafted requests to modify inventory records.

The issue allows users to modify data beyond their permitted role.


2) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify party records beyond their permitted role.

The vulnerability exists due to missing authorization in certain endpoints when handling requests to modify party records. A remote user can send a crafted request to modify party records beyond their permitted role.


3) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify data beyond their permitted role.

The vulnerability exists due to missing authorization in certain endpoints when handling requests. A remote user can send crafted requests to modify data beyond their permitted role.


4) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute script in the browser of an operator who opens the affected page.

The vulnerability exists due to cross-site scripting in record name rendering when processing item master data displayed on the affected page. A remote user can store a crafted record name to execute script in the browser of an operator who opens the affected page.

User interaction is required, and exploitation requires write access to item master data.


5) SQL injection (CVE-ID: N/A)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to SQL injection in some endpoints when handling specially crafted requests. A remote user can send a specially crafted request to disclose sensitive information.


6) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create unauthorized records and enumerate feature availability.

The vulnerability exists due to missing authorization in certain endpoints when handling record creation requests. A remote attacker can send crafted requests to create unauthorized records and enumerate feature availability.

The issue can be exploited even when the administrator has turned the feature off.


7) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in certain endpoints when handling requests. A remote attacker can send requests to read data beyond their permitted role to disclose sensitive information.


Remediation

Install update from vendor's website.