CVE-2026-44442

CRITICAL

ERPNext: Unauthorised Document modification due to missing validation

Title source: cna
STIX 2.1

Description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

References (1)

Core 1
Core References

Scores

CVSS v3 9.9
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
frappe/erpnext < 16.9.1 (2 CPE variants)
Published May 13, 2026
Tracked Since May 14, 2026