PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96672 Frappe CVE debrief

Frappe ERPNext versions before 16.34.1 have a vulnerability where Financial Report Template calculation_formula values are not validated to reference whitelisted methods before being passed to frappe.call(). This allows Accounts Managers to supply arbitrary dotted Python paths, potentially invoking non-whitelisted internal server-side methods and reading their return values.

Vendor
Frappe
Product
ERPNext
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-23
Original CVE updated
2026-09-29
Advisory published
2026-09-23
Advisory updated
2026-09-29

Who should care

Defenders responsible for ERPNext deployments, particularly those using Financial Report Templates, should assess exposure and prioritize verification and remediation efforts. This includes Accounts Managers, Security Teams, and IT personnel who manage ERPNext systems and need to ensure the security and integrity of financial data. Additionally, vulnerability management teams and security analysts should be aware of this vulnerability and its potential

Why it matters

Defenders should care about CVE-2026-96672 because it allows Accounts Managers to potentially invoke non-whitelisted internal server-side methods and read their return values, impacting ERPNext deployments using Financial Report Templates. Verification and remediation efforts are necessary to prevent potential unauthorized method invocations and data exposure.

  • Potential unauthorized method invocation and data exposure
  • Verification of Financial Report Template configurations and user input validation
  • Upgrade to version 16.34.1 or later to address the vulnerability

Technical summary

The vulnerability exists in Frappe ERPNext versions before 16.34.1, where Financial Report Template calculation_formula values are not properly validated, allowing Accounts Managers to supply arbitrary dotted Python paths. This could potentially lead to the invocation of non-whitelisted internal server-side methods and reading their return values. The issue arises from inadequate validation of user-supplied input, which can be exploited by Accounts Managers to access sensitive information. To mitigate this vulnerability, it is essential to upgrade to version 16.34.1 or later and review Financial Report Template configurations for potential unauthorized method invocations.

Defensive priority

Defenders should prioritize verifying and upgrading to version 16.34.1 or later, and review Financial Report Template configurations for potential unauthorized method invocations.

Recommended defensive actions

  • Verify and upgrade to version 16.34.1 or later
  • Review Financial Report Template configurations for potential unauthorized method invocations
  • Monitor for suspicious activity related to Financial Report Template usage
  • Perform vulnerability scanning to identify exposed systems
  • Review system logs for signs of potential exploitation
  • Implement additional security controls to prevent unauthorized access
  • Conduct a thorough risk assessment to identify potential impacts

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description and affected versions. However, the corpus does not establish specific exploitation instances or remediation beyond upgrading to version 16.34.1 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96672 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96672

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96672 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96672

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.