Skip to content

CVE-2026-65974 CVE-2026-12895 CVE-2026-72908 CVE-2026-72907

ERPNext updates fix server-side template injection, SQL injection and broken access control (CVE-2026-65974)

Critical 9.9 Vendor: Frappe / ERPNext Published

ERPNext before 15.111.0 and 16.22.0 has a critical server-side template injection allowing remote code execution for low-privileged authenticated users, plus SQL injection and broken access control. Fixed releases are available; update to the latest patched version.

What happened

CVE-2026-65974 is a server-side template injection in Frappe's safe execution. Because frappe.render_template is exposed without forcing restrict_globals, a limited authenticated user can cross a permission boundary and achieve remote code execution on the ERPNext server. The CVSS 3.1 vector is network-based, low attack complexity, low privileges, no user interaction, with high impact on confidentiality, integrity and availability, and a score of 9.9.

Two SQL injection flaws are also included. CVE-2026-12895 allows an authenticated low-privileged user to exploit supplier records whose names contain SQL metacharacters, bypass Frappe's DocPerm access restrictions, and extract confidential information including fragments of the administrator's password hash, credentials, integration tokens or financial data. CVE-2026-72908 allows injection through the tax rule get_tax_template function to extract sensitive information.

CVE-2026-72907 is a broken access control in the add_ac function; an authenticated limited user can create unauthorized accounting master records, affecting financial data integrity and audit trails. The CVE records do not report exploitation in the wild, and none of these flaws are listed in CISA's KEV catalogue.

Who is affected

ERPNext is an open source enterprise resource planning tool; deployments often manage financial, inventory and customer records. Affected releases are ERPNext 15.x before 15.111.0 and ERPNext 16.0.0 through before 16.22.0 for the template injection, the supplier SQL injection and the broken access control. The tax rule SQL injection affects versions before 15.109.0 and 16.0.0 through before 16.20.0. If you run any 15.x release below 15.111.0 or any 16.x release below 16.22.0, treat this bundle as applicable.

What to do now

  1. Apply the latest fixed release for your branch. Frappe's GitHub advisories list 15.111.0 and 16.22.0 for the critical template injection and supplier SQL injection, 15.109.0 and 16.20.0 for the tax rule SQL injection, and 15.112.0 and 16.23.0 for the access-control fix GHSA-94v6-784v-24q5. To cover all four flaws, update to at least 15.112.0 or 16.23.0, or a later release.
  2. No workaround is listed in Frappe's advisories for these flaws. If you cannot update immediately, restrict access to the ERPNext web interface to trusted internal users and avoid exposing it to the public internet, especially any supplier-facing or self-service portal.
  3. After updating, review low-privileged accounts, supplier records and accounting master data for unexpected entries. Rotate any credentials or integration tokens that could have been exposed by the SQL injection.

How to detect it

No indicators of compromise are listed in Frappe's advisories for these flaws. Based on the vulnerability descriptions, review supplier records for names containing SQL metacharacters such as quotes or brackets, monitor for creation of accounting master records by users who should not have Account create permission, and investigate unexplained changes to tax rules or template rendering errors on affected systems.

Beyond the patch

ERPNext instances often hold the financial and customer data that makes SQL injection and arbitrary account creation especially damaging, so the important work after patching is confirming that no low-privileged access already left a foothold. If users or suppliers can authenticate over the internet, Managed Detection & Response (MDR) can watch for the code execution and credential abuse these flaws enable, and an Implementation & Assessment Services review can verify the instance is hardened before it returns to service.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-65974
erpnext
< 15.111.0
>= 16.0.0, < 16.22.0
0, 16.22.0
CVE-2026-12895
ERPNext
– < 15.111.0
– < 16.22.0
15.111.0
16.22.0
0, 16.22.0
CVE-2026-72908
erpnext
< 15.109.0
>= 16.0.0, < 16.20.0
0, 16.20.0
CVE-2026-72907
erpnext
< 15.111.0
>= 16.0.0, < 16.22.0
0, 16.23.0

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.