CVE-2026-55242

HIGH

ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix

Title source: cna
STIX 2.1

Description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1336 CWE-863
Status published
Products (2)
frappe/erpnext < 15.111.0
frappe/erpnext >= 16.0.0, < 16.22.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026