GHSA-x635-wr4c-7345 GHSA-6w83-8777-v93q GHSA-8pr6-r75h-h8xx GHSA-rg9g-c26v-cw27 CVE-2026-66001 GHSA-c496-q7g2-62vv CVE-2026-65822 CVE-2026-62315 CVE-2026-66002 CVE-2026-63654
Frappe and ERPNext advisories: privilege escalation, SSTI, XSS, SQL injection and CSRF (CVE-2026-66001, CVE-2026-65822)
Frappe disclosed ten advisories affecting ERPNext. Critical flaws let an authenticated user create privileged accounts or read, write and delete data via template injection; others include stored XSS, SQL injection and CSRF. Apply fixes; two medium Frappe flaws have no fix. No active exploitation.
What happened
Frappe published the ERPNext advisories on 13 and 14 August 2026, with the CVE records added on 17 and 20 August. They form one bundle: the underlying issue is missing authorization and validation around user-controllable input. GHSA-x635-wr4c-7345 lets any authenticated user, including one with no operational role, create privileged accounts and take full control of the site. GHSA-6w83-8777-v93q lets an authenticated user with a common operational role perform server-side template injection with an unrestricted context, giving arbitrary database read and write, document deletion, outbound requests from the server, and mail sent by the site.
The remaining flaws cover stored cross-site scripting that can take over a privileged user's or administrator's account (GHSA-8pr6-r75h-h8xx and GHSA-rg9g-c26v-cw27), SQL injection in the Inactive Customers report (CVE-2026-65822), unauthorised record modification (GHSA-c496-q7g2-62vv), an OAuth consent weakness (CVE-2026-66001), mass assignment (CVE-2026-62315), user enumeration (CVE-2026-66002) and workflow approval through safe HTTP methods (CVE-2026-63654). None of the flaws is listed in CISA KEV, and none is reported as exploited.
Who is affected
ERPNext and the underlying Frappe framework are affected. The fixed releases are separate per branch and flaw; verify the table on this page against your deployment.
ERPNext:
- GHSA-x635-wr4c-7345: before 15.111.0 and before 16.22.0
- GHSA-6w83-8777-v93q: before 15.119.1 and before 16.32.0
- GHSA-8pr6-r75h-h8xx: before 15.119.0 and before 16.31.0
- GHSA-rg9g-c26v-cw27: before 15.113.0 and before 16.24.0
- GHSA-c496-q7g2-62vv: before 16.22.0
- CVE-2026-65822: before 15.116.0 and from 16.0.0 before 16.23.0
Frappe:
- CVE-2026-66001: before 15.114.0 and from 16.0.0-beta.1 before 16.26.0
- CVE-2026-66002: before 15.115.0 and from 16.0.0-beta.1 before 16.27.0
- CVE-2026-62315 and CVE-2026-63654: up to and including 16.31.0
What to do now
- Patch ERPNext first. Install 15.119.1 for ERPNext 15.x or 16.32.0 for ERPNext 16.x. These are the newest fixed versions named for the bundle; confirm each advisory's specific fixed build in the table above, particularly GHSA-c496-q7g2-62vv, which is fixed in 16.22.0.
- Patch Frappe next. Install 15.115.0 for Frappe 15.x or 16.27.0 for Frappe 16.x. These are the newest fixed builds for the fixed Frappe flaws.
- No vendor workaround is published for the fixed advisories; upgrading is required.
- For CVE-2026-62315 and CVE-2026-63654, no released fixed version is available. Restrict access to the application to trusted users and networks, and monitor for anomalous workflow approvals and mass assignment through the client endpoint until a fix is published.
How to detect it
Review ERPNext role and user lists for privileged accounts that do not match joiners, transfers or leavers, because the privilege escalation flaw creates accounts with permission checks disabled. Audit message templates and document histories for unusual database writes, deletions, outbound requests or mail, matching the server-side template injection flaw. Check workflow approval logs for approvals submitted by safe HTTP methods, and review OAuth consent grants for unexpected clients. These are investigation leads from the advisory descriptions rather than vendor-published indicators.
Beyond the patch
ERPNext holds financial, inventory and employee data, so an authenticated user escalating to admin or reading through template injection is an internal data confidentiality and integrity incident as much as a patch item. Use Managed Detection & Response (MDR) to detect the credential abuse, account creation and unusual database activity these flaws enable. Use Supply Chain Defense & Third-Party Risk to track Frappe/ERPNext patch cadence, because two medium Frappe flaws have no fix yet and supplier release timing sets your exposure window.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-x635-wr4c-7345 ERPNext | – < 15.111.0 – < 16.22.0 | 15.111.0 16.22.0 0, 16.22.0 |
| GHSA-6w83-8777-v93q ERPNext | – < 15.119.1 – < 16.32.0 | 15.119.1 16.32.0 1, 16.32.0 |
| GHSA-8pr6-r75h-h8xx ERPNext | – < 15.119.0 – < 16.31.0 | 15.119.0 16.31.0 0, 16.31.0 |
| GHSA-rg9g-c26v-cw27 ERPNext | – < 15.113.0 – < 16.24.0 | 15.113.0 16.24.0 0, 16.24.0 |
| CVE-2026-66001 frappe | < 15.114.0 >= 16.0.0-beta.1, < 16.26.0 | .0, 16.26.0 |
| GHSA-c496-q7g2-62vv ERPNext | – < 16.22.0 | 16.22.0 16.22.0 |
| CVE-2026-65822 erpnext | < 15.116.0 >= 16.0.0, < 16.23.0 | 0, 16.23.0 |
| CVE-2026-62315, CVE-2026-63654 frappe | <= 16.31.0 | No fixed version listed yet |
| CVE-2026-66002 frappe | < 15.115.0 >= 16.0.0-beta.1, < 16.27.0 | .0, 16.27.0 |
References
Vendor advisory
- Privilege escalation via unauthorised record creation
- Possibility of server-side template injection due to missing validation
- Account takeover via stored cross-site scripting
- Account takeover via stored cross-site scripting
- Improper Authorization in OAuth2 Consent Endpoint
- Unauthorised modification of records due to missing validation
- Possibility of SQL injection due to missing validation
- Mass assignment in client endpoint
Other
- github.com/frappe/frappe/pull/40073
- github.com/frappe/frappe/pull/40700
- github.com/frappe/frappe/pull/40701
- github.com/frappe/frappe/commit/336c7d335db762b494acdfe43aea69d459fd51d7
- github.com/frappe/frappe/commit/d7460769f999c68d3121b680119f8724ddd3eb9d
- github.com/frappe/frappe/commit/eb9c1446cac13236c6d573b136786db2e46254fa
- github.com/frappe/frappe/releases/tag/v15.114.0
- github.com/frappe/frappe/releases/tag/v16.26.0
CVE / GHSA
- GHSA-x635-wr4c-7345 — GitHub
- GHSA-6w83-8777-v93q — GitHub
- GHSA-8pr6-r75h-h8xx — GitHub
- GHSA-rg9g-c26v-cw27 — GitHub
- CVE-2026-66001 — cve.org
- CVE-2026-66001 — NVD
- GHSA-c496-q7g2-62vv — GitHub
- CVE-2026-65822 — cve.org
- CVE-2026-65822 — NVD
- CVE-2026-62315 — cve.org
- CVE-2026-62315 — NVD
- CVE-2026-66002 — cve.org
- CVE-2026-66002 — NVD
- CVE-2026-63654 — cve.org
- CVE-2026-63654 — NVD