PatchSiren cyber security CVE debrief
CVE-2026-72910 frappe CVE debrief
ERPNext, a free and open-source Enterprise Resource Planning tool, had multiple functions lacking required write permission checks. This allowed authenticated limited users to modify protected data beyond their roles. The issue is fixed in versions 15.112.0 and 16.22.0. Affected deployments should be verified, and patches applied to prevent unauthorized data modification. Review user roles and permissions to ensure proper access controls. Monitor system logs for suspicious activity related to ERPNext.
- Vendor
- frappe
- Product
- erpnext
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-09
Who should care
Defenders and administrators of ERPNext systems should assess exposure and apply patches to prevent unauthorized data modification. This includes reviewing user roles and permissions, monitoring system logs, and verifying the integrity of ERPNext deployments. Security teams should prioritize patching and verifying exposure to prevent potential data breaches.
Why it matters
CVE-2026-72910 allows authenticated limited users to modify protected data beyond their roles in ERPNext. Defenders should prioritize verifying exposure and applying patches.
- Verify exposure and apply patches for ERPNext versions prior to 15.112.0 and 16.22.0
- Review user roles and permissions to prevent unauthorized data modification
- Monitor system logs for suspicious activity
Technical summary
The merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions in ERPNext lacked required write permission checks. This allowed authenticated limited users to modify protected data beyond their roles. The issue is fixed in versions 15.112.0 and 16.22.0. Affected systems should be reviewed for exposure, and patches applied. Technical details are limited to publicly available sources, and defenders should exercise caution when verifying exposure. ERPNext deployments should prioritize patching to prevent data modification.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for ERPNext versions prior to 15.112.0 and 16.22.0.
Recommended defensive actions
- Verify ERPNext version and apply patches if necessary
- Review user roles and permissions to prevent unauthorized data modification
- Monitor system logs for suspicious activity
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and affected versions. Multiple source references, including GitHub commits and release notes, support the issue and fix details. The vulnerability allows authenticated limited users to modify protected data beyond their roles in ERPNext versions prior to 15.112.0 and 16.22.0. Defenders should verify exposure and apply patches. Evidence is limited to public sources, and further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72910 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72910
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72910 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72910
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/commit/2ae6451f10926bd12b6ce6c7dc40f08da83f2460
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/commit/8c7a313a38dfe38c9e35ca41e91389bcfaed2404
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/commit/ba936eefabb784805daa4c602b4baec9fc243ff8
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/pull/55709
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/releases/tag/v15.112.0
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/releases/tag/v16.22.0
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/security/advisories/GHSA-qpvh-75wh-j645
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.