PT-2026-40825 · Frappe · Erpnext

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-44448

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ERPNext versions prior to 15.102.0 ERPNext versions prior to 16.11.0
Description Certain endpoints fail to enforce proper authorization checks, which allows users to modify data beyond the permissions assigned to their role.
Recommendations Update to version 15.102.0. Update to version 16.11.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-44448

Affected Products

Erpnext