Missing Authorization in ERPNext - #VU142684
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to create unauthorized records and enumerate feature availability.
The vulnerability exists due to missing authorization in certain endpoints when handling record creation requests. A remote attacker can send crafted requests to create unauthorized records and enumerate feature availability.
The issue can be exploited even when the administrator has turned the feature off.