PT-2026-40821 · Erpnext · Erpnext

·

CVE-2026-44442

·

Published

2026-05-13

·

Updated

2026-05-15

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ERPNext versions prior to 16.9.1
Description Certain endpoints in this open source Enterprise Resource Planning tool fail to enforce proper authorization checks, which allows users to modify data beyond the permissions assigned to their role.
Recommendations Update to version 16.9.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44442
GHSA-CG5W-7G26-P3W9

Affected Products

Erpnext