Missing Authorization in ERPNext - #VU142684

 

Missing Authorization in ERPNext - #VU142684

Published: August 15, 2026


Vulnerability identifier: #VU142684
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create unauthorized records and enumerate feature availability.

The vulnerability exists due to missing authorization in certain endpoints when handling record creation requests. A remote attacker can send crafted requests to create unauthorized records and enumerate feature availability.

The issue can be exploited even when the administrator has turned the feature off.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.110.0, 16.21.0

External References

Related Security Bulletins