CVE-2026-44445

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configuration files. This vulnerability is fixed in 15.104.3 and 16.12.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*
cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*

History

14 May 2026, 20:02

Type Values Removed Values Added
CPE cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*
First Time Frappe
Frappe erpnext
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/frappe/erpnext/security/advisories/GHSA-mhm9-75w7-423r - () https://github.com/frappe/erpnext/security/advisories/GHSA-mhm9-75w7-423r - Vendor Advisory

13 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 22:16

Updated : 2026-05-14 20:02


NVD link : CVE-2026-44445

Mitre link : CVE-2026-44445

CVE.ORG link : CVE-2026-44445


JSON object : View

Products Affected

frappe

  • erpnext
CWE
CWE-611

Improper Restriction of XML External Entity Reference