CVE-2026-13227
EUVD-2026-5292404.08.2026, 21:16
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| frappe | erpnext | 𝑥 < 15.115.0 | CNA |
| frappe | erpnext | 𝑥 < 16.26.0 | CNA |
Common Weakness Enumeration