Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72911: ERPNext: Malicious Code Can Execute on Server

CVE-2026-72911 · published 24 days ago
Summary

ERPNext users need to update to version 15.118.0 or 16.29.0 to prevent malicious code execution. This issue allowed an authenticated user to execute arbitrary server-side code and read sensitive data, but it has been fixed in the latest versions. Users should update their ERPNext installation as soon as possible to stay secure.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
frappe erpnext < 15.118.0
Original advisory text
ERPNext: Possibility of server-side template injection due to missing validation
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inject template expressions, execute arbitrary server-side code, and read data across the application. This issue is fixed in versions 15.118.0 and 16.29.0.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published10 Aug 2026
Updated30 Aug 2026
First seen10 Aug 2026
Sources
CVE-2026-72911 · MITRE
Monitor software like this
Free during beta