ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.
References
Configurations
No configuration.
History
15 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 16:16
Updated : 2026-07-15 20:49
NVD link : CVE-2026-55242
Mitre link : CVE-2026-55242
CVE.ORG link : CVE-2026-55242
JSON object : View
Products Affected
No product.
