CVE-2026-13227
published 2026-08-04CVE-2026-13227: An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method…
PriorityP339high7.1CVSS 4.0
AVNACLATNPRLUINVCHVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.25%
15.9th percentile
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.
This issue affects ERPNext: before 15.115.0, before 16.26.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| frappe | erpnext | < 15.115.0 | 15.115.0 |
| frappe | erpnext | < 16.26.0 | 16.26.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://fluidattacks.com/es/advisories/kravizhttps://github.com/frappe/erpnexthttps://github.com/frappe/erpnext/releases?page=2#release-v15.115.0https://github.com/frappe/erpnext/releases?page=2#release-v16.26.0https://github.com/frappe/erpnext/security/advisories/GHSA-g8r3-82j6-wp48https://fluidattacks.com/es/advisories/kraviz
2026-08-04
Published