ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* |
Wed, 13 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| Vendors & Products |
Frappe
Frappe erpnext |
Wed, 13 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1. | |
| Title | ERPNext: Unauthorised Document modification due to missing validation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T19:52:05.513Z
Reserved: 2026-05-06T14:40:00.955Z
Link: CVE-2026-44442
Updated: 2026-05-14T16:04:00.465Z
Status : Analyzed
Published: 2026-05-13T22:16:45.350
Modified: 2026-05-14T20:04:02.837
Link: CVE-2026-44442
No data.
OpenCVE Enrichment
Updated: 2026-05-13T22:30:06Z