Missing Authorization in ERPNext - #VU151477
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote user to create documents against records beyond their permitted role.
The vulnerability exists due to missing authorization in certain endpoints when handling document-creation requests. A remote user can send document-creation requests to create documents against records beyond their permitted role.