High severity8.8NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-55242
CVE-2026-55242
Description
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.