Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - CVE-2026-72911

 

Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - CVE-2026-72911

Published: August 13, 2026


Vulnerability identifier: #VU142376
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72911
CWE-ID: CWE-1336
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in a template engine in certain fields rendered as server-side templates when processing user-supplied template expressions. A remote user can inject crafted template expressions to execute arbitrary code.

The injected expressions are evaluated in an unrestricted execution context, and the issue can also expose data across the application.


Affected software

ERPNext

How to mitigate CVE-2026-72911

Install security update from vendor's website.

ERPNext - addressed in versions 15.118.0, 16.29.0

External References

Related Security Bulletins