Critical severity9.1NVD Advisory· Published Feb 21, 2026· Updated Jun 17, 2026
CVE-2026-27471
CVE-2026-27471
Description
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: <15.98.1
- cpe:2.3:a:frappe:erpnext:16.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:frappe:erpnext:16.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:frappe:erpnext:16.0.0:rc2:*:*:*:*:*:*
- (no CPE)range: <=15.98.0, 16.0.0-rc.1, <=16.6.0
- (no CPE)range: >= 16.0.0-rc.1, < 16.6.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.