Description
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Scores
CVSS v3
9.1
EPSS
0.0005
EPSS Percentile
14.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-862
CWE-306
CWE-284
Status
published
Products (2)
frappe/erpnext
16.0.0 (3 CPE variants)
frappe/erpnext
< 15.98.1
Published
Feb 21, 2026
Tracked Since
Feb 21, 2026