Unrated severityNVD Advisory· Published Feb 21, 2026· Updated Feb 24, 2026
ERP: Document access through endpoints due to missing validation
CVE-2026-27471
Description
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/frappe/erpnext/commit/78fc9424d9085c2eafe1211931e22d7044f85fc7mitrex_refsource_MISC
- github.com/frappe/erpnext/security/advisories/GHSA-wpfx-jw7g-7f83mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.