Skip to content

GHSA-x635-wr4c-7345 GHSA-6w83-8777-v93q GHSA-8pr6-r75h-h8xx GHSA-rg9g-c26v-cw27 CVE-2026-66001 GHSA-c496-q7g2-62vv CVE-2026-65822 CVE-2026-62315 CVE-2026-66002 CVE-2026-63654

Frappe and ERPNext advisories: privilege escalation, SSTI, XSS, SQL injection and CSRF (CVE-2026-66001, CVE-2026-65822)

Critical 9.9 Vendor: Frappe / ERPNext Published

Frappe disclosed ten advisories affecting ERPNext. Critical flaws let an authenticated user create privileged accounts or read, write and delete data via template injection; others include stored XSS, SQL injection and CSRF. Apply fixes; two medium Frappe flaws have no fix. No active exploitation.

What happened

Frappe published the ERPNext advisories on 13 and 14 August 2026, with the CVE records added on 17 and 20 August. They form one bundle: the underlying issue is missing authorization and validation around user-controllable input. GHSA-x635-wr4c-7345 lets any authenticated user, including one with no operational role, create privileged accounts and take full control of the site. GHSA-6w83-8777-v93q lets an authenticated user with a common operational role perform server-side template injection with an unrestricted context, giving arbitrary database read and write, document deletion, outbound requests from the server, and mail sent by the site.

The remaining flaws cover stored cross-site scripting that can take over a privileged user's or administrator's account (GHSA-8pr6-r75h-h8xx and GHSA-rg9g-c26v-cw27), SQL injection in the Inactive Customers report (CVE-2026-65822), unauthorised record modification (GHSA-c496-q7g2-62vv), an OAuth consent weakness (CVE-2026-66001), mass assignment (CVE-2026-62315), user enumeration (CVE-2026-66002) and workflow approval through safe HTTP methods (CVE-2026-63654). None of the flaws is listed in CISA KEV, and none is reported as exploited.

Who is affected

ERPNext and the underlying Frappe framework are affected. The fixed releases are separate per branch and flaw; verify the table on this page against your deployment.

ERPNext:

  • GHSA-x635-wr4c-7345: before 15.111.0 and before 16.22.0
  • GHSA-6w83-8777-v93q: before 15.119.1 and before 16.32.0
  • GHSA-8pr6-r75h-h8xx: before 15.119.0 and before 16.31.0
  • GHSA-rg9g-c26v-cw27: before 15.113.0 and before 16.24.0
  • GHSA-c496-q7g2-62vv: before 16.22.0
  • CVE-2026-65822: before 15.116.0 and from 16.0.0 before 16.23.0

Frappe:

  • CVE-2026-66001: before 15.114.0 and from 16.0.0-beta.1 before 16.26.0
  • CVE-2026-66002: before 15.115.0 and from 16.0.0-beta.1 before 16.27.0
  • CVE-2026-62315 and CVE-2026-63654: up to and including 16.31.0

What to do now

  1. Patch ERPNext first. Install 15.119.1 for ERPNext 15.x or 16.32.0 for ERPNext 16.x. These are the newest fixed versions named for the bundle; confirm each advisory's specific fixed build in the table above, particularly GHSA-c496-q7g2-62vv, which is fixed in 16.22.0.
  2. Patch Frappe next. Install 15.115.0 for Frappe 15.x or 16.27.0 for Frappe 16.x. These are the newest fixed builds for the fixed Frappe flaws.
  3. No vendor workaround is published for the fixed advisories; upgrading is required.
  4. For CVE-2026-62315 and CVE-2026-63654, no released fixed version is available. Restrict access to the application to trusted users and networks, and monitor for anomalous workflow approvals and mass assignment through the client endpoint until a fix is published.

How to detect it

Review ERPNext role and user lists for privileged accounts that do not match joiners, transfers or leavers, because the privilege escalation flaw creates accounts with permission checks disabled. Audit message templates and document histories for unusual database writes, deletions, outbound requests or mail, matching the server-side template injection flaw. Check workflow approval logs for approvals submitted by safe HTTP methods, and review OAuth consent grants for unexpected clients. These are investigation leads from the advisory descriptions rather than vendor-published indicators.

Beyond the patch

ERPNext holds financial, inventory and employee data, so an authenticated user escalating to admin or reading through template injection is an internal data confidentiality and integrity incident as much as a patch item. Use Managed Detection & Response (MDR) to detect the credential abuse, account creation and unusual database activity these flaws enable. Use Supply Chain Defense & Third-Party Risk to track Frappe/ERPNext patch cadence, because two medium Frappe flaws have no fix yet and supplier release timing sets your exposure window.

Affected and fixed versions

ProductAffectedFixed in
GHSA-x635-wr4c-7345
ERPNext
– < 15.111.0
– < 16.22.0
15.111.0
16.22.0
0, 16.22.0
GHSA-6w83-8777-v93q
ERPNext
– < 15.119.1
– < 16.32.0
15.119.1
16.32.0
1, 16.32.0
GHSA-8pr6-r75h-h8xx
ERPNext
– < 15.119.0
– < 16.31.0
15.119.0
16.31.0
0, 16.31.0
GHSA-rg9g-c26v-cw27
ERPNext
– < 15.113.0
– < 16.24.0
15.113.0
16.24.0
0, 16.24.0
CVE-2026-66001
frappe
< 15.114.0
>= 16.0.0-beta.1, < 16.26.0
.0, 16.26.0
GHSA-c496-q7g2-62vv
ERPNext
– < 16.22.016.22.0
16.22.0
CVE-2026-65822
erpnext
< 15.116.0
>= 16.0.0, < 16.23.0
0, 16.23.0
CVE-2026-62315, CVE-2026-63654
frappe
<= 16.31.0No fixed version listed yet
CVE-2026-66002
frappe
< 15.115.0
>= 16.0.0-beta.1, < 16.27.0
.0, 16.27.0

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.