ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
References
Configurations
Configuration 1 (hide)
|
History
24 Feb 2026, 14:52
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CPE | cpe:2.3:a:frappe:erpnext:16.0.0:-:*:*:*:*:*:* cpe:2.3:a:frappe:erpnext:16.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:frappe:erpnext:16.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* |
|
| First Time |
Frappe erpnext
Frappe |
|
| References | () https://github.com/frappe/erpnext/commit/78fc9424d9085c2eafe1211931e22d7044f85fc7 - Patch | |
| References | () https://github.com/frappe/erpnext/security/advisories/GHSA-wpfx-jw7g-7f83 - Vendor Advisory |
23 Feb 2026, 18:13
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
21 Feb 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-21 07:16
Updated : 2026-02-24 14:52
NVD link : CVE-2026-27471
Mitre link : CVE-2026-27471
CVE.ORG link : CVE-2026-27471
JSON object : View
Products Affected
frappe
- erpnext
