Improper Authorization in ERPNext - #VU140796

 

Improper Authorization in ERPNext - #VU140796

Published: August 3, 2026


Vulnerability identifier: #VU140796
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create unauthorized accounting master records.

The vulnerability exists due to improper authorization in a certain endpoint when handling requests. A remote user can send crafted requests to create unauthorized accounting master records.

This may affect financial data integrity and audit trails.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.112.0, 16.23.0

External References

Related Security Bulletins