Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-65974: ERPNext: Attackers can run code on your server
CVE-2026-65974 · published 17 days ago
Summary
ERPNext users with limited access may be able to run unauthorized code on your server. This could allow hackers to access sensitive data or take control of your system. Update to the latest version of ERPNext to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| frappe | erpnext | < 15.111.0 |
Original advisory text
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frap...
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
References
- https://github.com/frappe/erpnext/releases/tag/v15.111.0
- https://github.com/frappe/erpnext/releases/tag/v16.22.0
- https://github.com/frappe/erpnext/security/advisories/GHSA-w996-r7v3-87wr
- https://github.com/frappe/frappe/commit/529d190a252863672164d10bfcd91d1de0ac1c7c
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65974... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-65974 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta