Junglewise Threat Intelligence

CVE-2026-44447: Frappe ERPNext SQL injection in multiple endpoints

CVE-2026-44447 · Severity: high · CVSS 8.8 · Published 2026-05-13

Vendors: Frappe Technologies.

Executive brief

ERPNext, an open-source enterprise resource planning (ERP) platform, is vulnerable to a security flaw that could allow an attacker to access or modify sensitive business data. By sending specially crafted requests to certain parts of the system, a malicious user with basic account access could bypass security controls to extract private information or disrupt operations. This could lead to the exposure of financial records, customer data, or internal business secrets.

Technical details

A SQL injection vulnerability (CWE-89) exists in ERPNext due to improper neutralization of user-supplied input in certain API endpoints. An attacker with low-privileged network access can send specially crafted requests to these endpoints to execute arbitrary SQL commands against the backend database. This can result in the unauthorized extraction of sensitive data, modification of records, or full database compromise. The vulnerability is present in versions prior to 16.9.0 and has been addressed in the 16.9.0 release. No workarounds are available other than upgrading.

Affected products

  • Frappe Technologies ERPNext < 16.9.0

Timeline

  • 2026-04-30: advisory: GitHub Security Advisory published by Frappe
  • 2026-05-13: disclosed: CVE-2026-44447 published to the NVD

References