CVE-2026-27471
CRITICALERP <=15.98.0/16.0.0-rc.1-16.6.0 - Auth Bypass
Title source: llmDescription
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Scores
CVSS v3
9.1
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-862
CWE-306
CWE-284
Status
published
Affected Products (4)
frappe/erpnext
< 15.98.1
frappe/erpnext
frappe/erpnext
frappe/erpnext
Timeline
Published
Feb 21, 2026
Tracked Since
Feb 21, 2026