Unrated severityNVD Advisory· Published Feb 21, 2026· Updated Feb 24, 2026
ERP: Document access through endpoints due to missing validation
CVE-2026-27471
Description
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/frappe/erpnext/commit/78fc9424d9085c2eafe1211931e22d7044f85fc7mitrex_refsource_MISC
- github.com/frappe/erpnext/security/advisories/GHSA-wpfx-jw7g-7f83mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.