PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72910 frappe CVE debrief

ERPNext, a free and open-source Enterprise Resource Planning tool, had multiple functions lacking required write permission checks. This allowed authenticated limited users to modify protected data beyond their roles. The issue is fixed in versions 15.112.0 and 16.22.0. Affected deployments should be verified, and patches applied to prevent unauthorized data modification. Review user roles and permissions to ensure proper access controls. Monitor system logs for suspicious activity related to ERPNext.

Vendor
frappe
Product
erpnext
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-09
Advisory published
2026-08-10
Advisory updated
2026-09-09

Who should care

Defenders and administrators of ERPNext systems should assess exposure and apply patches to prevent unauthorized data modification. This includes reviewing user roles and permissions, monitoring system logs, and verifying the integrity of ERPNext deployments. Security teams should prioritize patching and verifying exposure to prevent potential data breaches.

Why it matters

CVE-2026-72910 allows authenticated limited users to modify protected data beyond their roles in ERPNext. Defenders should prioritize verifying exposure and applying patches.

  • Verify exposure and apply patches for ERPNext versions prior to 15.112.0 and 16.22.0
  • Review user roles and permissions to prevent unauthorized data modification
  • Monitor system logs for suspicious activity

Technical summary

The merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions in ERPNext lacked required write permission checks. This allowed authenticated limited users to modify protected data beyond their roles. The issue is fixed in versions 15.112.0 and 16.22.0. Affected systems should be reviewed for exposure, and patches applied. Technical details are limited to publicly available sources, and defenders should exercise caution when verifying exposure. ERPNext deployments should prioritize patching to prevent data modification.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for ERPNext versions prior to 15.112.0 and 16.22.0.

Recommended defensive actions

  • Verify ERPNext version and apply patches if necessary
  • Review user roles and permissions to prevent unauthorized data modification
  • Monitor system logs for suspicious activity
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. Multiple source references, including GitHub commits and release notes, support the issue and fix details. The vulnerability allows authenticated limited users to modify protected data beyond their roles in ERPNext versions prior to 15.112.0 and 16.22.0. Defenders should verify exposure and apply patches. Evidence is limited to public sources, and further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72910 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72910

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72910 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72910

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.