CVE-2026-27471
EUVD-2026-772721.02.2026, 07:16
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | erpnext | 𝑥 < 15.98.1 |
| frappe | erpnext | 16.0.0 < 𝑥 < 16.6.1 |
| frappe | erpnext | 16.0.0 |
| frappe | erpnext | 16.0.0:rc1 |
| frappe | erpnext | 16.0.0:rc2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration