Junglewise Threat Intelligence

CVE-2026-13227: ERPNext improper authorization in Prospect opportunities API

CVE-2026-13227 · Severity: info · Published 2026-08-04

Technologies: Frappe ERPNext. Vendors: Frappe.

Executive brief

ERPNext is a popular open-source ERP (Enterprise Resource Planning) system used by businesses to manage operations and customer relationships. A flaw in the API method that retrieves prospect opportunities allows unauthorized users to access data they should not be able to view, potentially exposing sensitive business information about sales prospects and opportunities.

Technical details

This vulnerability is an improper authorization flaw in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. The vulnerable component fails to enforce adequate access controls, allowing authenticated users or potentially unauthenticated callers to retrieve prospect opportunity data they are not authorized to access. The attack vector is network-based, requiring only network reachability to the ERPNext instance. An attacker can exploit this to enumerate and access confidential business opportunities and prospect information. Patches are available in ERPNext versions 16.26.0 and 15.115.0 or later.

Affected products

  • Frappe ERPNext before 15.115.0, before 16.26.0

Timeline

  • 2026-08-04: disclosed

References

Related threats