Missing Authorization in ERPNext - #VU142395
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to trigger unauthorized transactional email and disclose limited information.
The vulnerability exists due to missing authorization in certain endpoints when handling requests to send transactional email for documents. A remote user can trigger email delivery for documents they are not permitted to read to trigger unauthorized transactional email and disclose limited information.