Junglewise Threat Intelligence

CVE-2026-44448: Frappe ERPNext missing authorization in document endpoints

CVE-2026-44448 · Severity: medium · CVSS 5.9 · Published 2026-05-13

Technologies: Frappe ERPNext. Vendors: Frappe.

Executive brief

ERPNext, an open-source enterprise resource planning tool used for managing business operations like accounting and inventory, contains a security flaw in how it handles user permissions. This vulnerability allows an authenticated user to bypass intended restrictions and modify business data or documents they should not have access to. Exploiting this could lead to unauthorized changes in financial or operational records, potentially impacting data integrity and confidentiality.

Technical details

A missing authorization vulnerability (CWE-862) exists in ERPNext prior to versions 15.102.0 and 16.11.0. Certain API endpoints fail to validate whether the requesting user has the appropriate role-based permissions to modify specific documents or data records. An attacker with low-privileged network access can exploit this to perform unauthorized data modifications, though the attack complexity is rated as high, suggesting specific conditions or knowledge of the target environment may be required. The issue is resolved in versions 15.102.0 and 16.11.0.

Affected products

  • Frappe ERPNext < 15.102.0, < 16.11.0

Timeline

  • 2026-04-30: advisory: GitHub Security Advisory published by the vendor.
  • 2026-05-13: disclosed: CVE published to the NVD.

References

Related threats