Improper Authorization in ERPNext - CVE-2026-72907
Published: August 3, 2026 / Updated: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to create unauthorized accounting master records.
The vulnerability exists due to improper authorization in a certain endpoint when handling requests. A remote user can send crafted requests to create unauthorized accounting master records.
This may affect financial data integrity and audit trails.