Improper Authorization in ERPNext - #VU140796
Published: August 3, 2026
Vulnerability identifier: #VU140796
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to create unauthorized accounting master records.
The vulnerability exists due to improper authorization in a certain endpoint when handling requests. A remote user can send crafted requests to create unauthorized accounting master records.
This may affect financial data integrity and audit trails.
Affected software
ERPNext
Remediation
Install security update from vendor's website.
ERPNext - addressed in versions 15.112.0, 16.23.0