Missing Authorization in ERPNext - #VU142383
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in a record-creation endpoint when handling record creation requests that take the record type from user-supplied input and insert records with permission checks disabled. A remote user can send a specially crafted request to escalate privileges.
This can allow creation of privileged accounts and lead to full control of the site.