Missing Authorization in ERPNext - #VU142383

 

Missing Authorization in ERPNext - #VU142383

Published: August 13, 2026


Vulnerability identifier: #VU142383
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to missing authorization in a record-creation endpoint when handling record creation requests that take the record type from user-supplied input and insert records with permission checks disabled. A remote user can send a specially crafted request to escalate privileges.

This can allow creation of privileged accounts and lead to full control of the site.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.111.0, 16.22.0

External References

Related Security Bulletins