CVE-2026-72911 CVE-2026-13227 CVE-2026-72909 CVE-2026-72910 CVE-2026-72906
ERPNext server-side template injection and related access-control flaws (CVE-2026-72911 and others)
ERPNext before 15.118.0 and 16.x before 16.29.0: a server-side template injection flaw lets an authenticated user with a common operational role run server-side code; four related access-control flaws affect earlier releases. Upgrade to 15.118.0 or 16.29.0.
What happened
The most serious issue is CVE-2026-72911, a server-side template injection in the Process Statement of Accounts function. An authenticated user with a common operational role can inject template expressions because the subject, body and pdf_name fields are rendered with unrestricted globals, including frappe.utils. That allows execution of arbitrary server-side code and reading data across the application. It is rated 9.9 critical and is reachable over the network with low attack complexity, low privileges and no user interaction.
Four further flaws are access-control weaknesses. CVE-2026-13227 lets any authenticated user call a whitelisted API method and read prospect opportunity data without proper authorisation. CVE-2026-72909 means any authenticated user can read unauthorised cross-company financial data in Accounts Receivable and Accounts Payable reports. CVE-2026-72910 lets limited users modify protected data such as accounts, payment reconciliation jobs, purchase invoice release dates and cost centres because required write-permission checks are missing. CVE-2026-72906 allows an authenticated low-privilege user to trigger automated emails outside the permitted role.
No exploitation in the wild or public disclosure is recorded for any of these flaws.
Who is affected
ERPNext is an open-source ERP system that centralises financial, customer and operational records, and is often self-hosted or exposed to employees and partners. The affected versions are:
- ERPNext before 15.118.0, and ERPNext 16.0.0 and later before 16.29.0, for CVE-2026-72911.
- ERPNext before 15.115.0 and before 16.26.0 for CVE-2026-13227.
- ERPNext before 15.112.0, and ERPNext 16.0.0 and later before 16.23.0, for CVE-2026-72909.
- ERPNext before 15.112.0, and ERPNext 16.0.0 and later before 16.22.0, for CVE-2026-72910.
- ERPNext before 15.111.0, and ERPNext 16.0.0 and later before 16.22.0, for CVE-2026-72906.
If you run any ERPNext release before 15.118.0, or any 16.x release before 16.29.0, at least one of these flaws applies to your instance.
What to do now
- Upgrade to the fixed release for your branch. The releases are: 15.118.0 or 16.29.0 for CVE-2026-72911; 15.115.0 or 16.26.0 for CVE-2026-13227; 15.112.0 or 16.23.0 for CVE-2026-72909; 15.112.0 or 16.22.0 for CVE-2026-72910; and 15.111.0 or 16.22.0 for CVE-2026-72906. The newest fixed versions shown are 15.118.0 and 16.29.0; upgrading to those addresses the critical template-injection flaw.
- No vendor workaround has been published for these flaws. If you cannot upgrade immediately, restrict network access to the ERPNext instance and limit roles that can use Process Statement of Accounts and the CRM Prospect API.
- After upgrading, confirm the exact version in the About/System information screen and re-check role assignments for users with accounts or purchasing privileges.
Beyond the patch
ERPNext concentrates financial and operational data in one place, so access-control failures and template injection turn low-privileged accounts into a serious exposure. Beyond patching, have the instance's role and permission model reviewed. Implementation & Assessment Services covers penetration testing and hardening for exposed ERP deployments, and Supply Chain Defense & Third-Party Risk helps track patch cycles and exposure windows for open-source components such as ERPNext.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-72911 erpnext | < 15.118.0 >= 16.0.0, < 16.29.0 | 0, 16.29.0 |
| CVE-2026-13227 ERPNext | – < 15.115.0 – < 16.26.0 | 15.115.0 16.26.0 0, 16.26.0 |
| CVE-2026-72909 erpnext | < 15.112.0 >= 16.0.0, < 16.23.0 | 0, 16.23.0 |
| CVE-2026-72910 erpnext | < 15.112.0 >= 16.0.0, < 16.22.0 | 0, 16.22.0 |
| CVE-2026-72906 erpnext | < 15.111.0 >= 16.0.0, < 16.22.0 | 0, 16.22.0 |
References
Vendor advisory
Patch and release notes
Exploit and analysis
Other
- github.com/frappe/erpnext/pull/56458
- github.com/frappe/erpnext/commit/5f6952b15c1f6ee893770d5bc618558a6ba41a28
- github.com/frappe/erpnext/commit/88443e4a97c6c0a40d85a9e6785577191296ee39
- github.com/frappe/erpnext/commit/ecb6d48ec025e0c94abac35b2e4f7607f4c86465
- github.com/frappe/erpnext/releases/tag/v15.118.0
- github.com/frappe/erpnext/releases/tag/v16.29.0
- github.com/frappe/erpnext
- github.com/frappe/erpnext/pull/55696