← back
CVE-2026-44448mediumCWE-862

ERPNext: Unauthorised Document modification due to missing validation

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
frappe · erpnext