PatchSiren cyber security CVE debrief
CVE-2026-96672 Frappe CVE debrief
Frappe ERPNext versions before 16.34.1 have a vulnerability where Financial Report Template calculation_formula values are not validated to reference whitelisted methods before being passed to frappe.call(). This allows Accounts Managers to supply arbitrary dotted Python paths, potentially invoking non-whitelisted internal server-side methods and reading their return values.
- Vendor
- Frappe
- Product
- ERPNext
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for ERPNext deployments, particularly those using Financial Report Templates, should assess exposure and prioritize verification and remediation efforts. This includes Accounts Managers, Security Teams, and IT personnel who manage ERPNext systems and need to ensure the security and integrity of financial data. Additionally, vulnerability management teams and security analysts should be aware of this vulnerability and its potential
Why it matters
Defenders should care about CVE-2026-96672 because it allows Accounts Managers to potentially invoke non-whitelisted internal server-side methods and read their return values, impacting ERPNext deployments using Financial Report Templates. Verification and remediation efforts are necessary to prevent potential unauthorized method invocations and data exposure.
- Potential unauthorized method invocation and data exposure
- Verification of Financial Report Template configurations and user input validation
- Upgrade to version 16.34.1 or later to address the vulnerability
Technical summary
The vulnerability exists in Frappe ERPNext versions before 16.34.1, where Financial Report Template calculation_formula values are not properly validated, allowing Accounts Managers to supply arbitrary dotted Python paths. This could potentially lead to the invocation of non-whitelisted internal server-side methods and reading their return values. The issue arises from inadequate validation of user-supplied input, which can be exploited by Accounts Managers to access sensitive information. To mitigate this vulnerability, it is essential to upgrade to version 16.34.1 or later and review Financial Report Template configurations for potential unauthorized method invocations.
Defensive priority
Defenders should prioritize verifying and upgrading to version 16.34.1 or later, and review Financial Report Template configurations for potential unauthorized method invocations.
Recommended defensive actions
- Verify and upgrade to version 16.34.1 or later
- Review Financial Report Template configurations for potential unauthorized method invocations
- Monitor for suspicious activity related to Financial Report Template usage
- Perform vulnerability scanning to identify exposed systems
- Review system logs for signs of potential exploitation
- Implement additional security controls to prevent unauthorized access
- Conduct a thorough risk assessment to identify potential impacts
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and affected versions. However, the corpus does not establish specific exploitation instances or remediation beyond upgrading to version 16.34.1 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96672 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96672
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96672 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96672
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_engine.py
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_template.json
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/commit/7aad59b129711e9bba17b25665428d1fc57bf37c
-
Source reference
Unverified legacy reference
URL: https://github.com/frappe/erpnext/security/advisories/GHSA-794x-fhm7-58j7
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/frappe-erpnext-before-16.34.1-unauthorized-method-invocation
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.