CVE-2026-72906
published 2026-08-10CVE-2026-72906: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.20%
10.7th percentile
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails outside the permitted role. This issue is fixed in versions 15.111.0 and 16.22.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| frappe | erpnext | < 15.111.0 | 15.111.0 |
| frappe | erpnext | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/frappe/erpnext/commit/18ca96c36ba65362bf1c25abb8eab32c64c6c7ddhttps://github.com/frappe/erpnext/commit/e15879acd118ccd343e31ad3b5a6279e514c82c2https://github.com/frappe/erpnext/pull/55781https://github.com/frappe/erpnext/releases/tag/v15.111.0https://github.com/frappe/erpnext/releases/tag/v16.22.0https://github.com/frappe/erpnext/security/advisories/GHSA-3x6c-gc4v-f5v8
2026-08-10
Published