CVE-2026-107841: pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
Impact
pacioli-guard's document-layer consent gate requires a human-minted, single-use, document-bound and act-bound marker before a credential carrying API Key Scope.requireconsent may submit or cancel a document. Because ERPNext performs further document writes as a consequence of a governed act, nested acts are allowed to "ride" the consent established by the enclosing act instead of needing a marker of their own.
The ride predicate returned true for every cancel, regardless of which act the enclosing marker authorised. Riding never reaches consentverdict, which is where the marker-to-act binding is enforced. The result: any Document.cancel() performed inside an act that had established consent reached docstatus = 2 with no marker, no act-binding check, no single-use spend, and no denial audit row.
This is reachable with the exact grant an operator is documented to give the broker, and the cancelled document's identity is caller-controlled:
- Sales Invoice.onsubmit (salesinvoice.py:507) calls processassetdepreciation() unconditionally, reaching depreciateassetonsale (:1508-1516). - That iterates the invoice's item rows and calls frappe.getdoc("Asset", d.asset). Sales Invoice Item.asset is a plain writable Link with no readonly and no fetchfrom, so the caller supplies it in the request body. The validation that would constrain it sits behind if d.isfixedasset: (:428-429), a server-set field. - The chain reaches depreciation.py:481 and then assetdepreciationschedule.py:215-217, which calls currentschedule.cancel() on a docstatus == 1, submittable Asset Depreciation Schedule through the document lifecycle (only shouldnotcanceldepreciationentries is set, not ignorevalidate, so beforecancel does fire and the ride is what admitted it).
So one marker authorising submit Sales Invoice X cancelled a submitted document the human was never shown and never approved. Cancelling such a document reverses its ledger effect.
The same shape exists behind wider grants, for example Unreconcile Payment.onsubmit (unreconcilepayment.py:59-64), which walks a child table the caller fills and reaches accounts/utils.py:857/:859 gainlossje.cancel() on submitted Journal Entries.
Who is affected
Only sites that had opted into consent gating: a credential must hold an API Key Scope with requireconsent set. pacioli-guard is inert for principals without such a grant, and the credential-scoping floor (authhooks) is unaffected by this issue.
The document-layer consent gate was first published in 0.9.6, which is the only released version in the affected range.
Patches
Fixed in 0.10.0. The ride now discriminates on the enclosing act: an undo may cascade into further undos, but a submit may not cascade into the cancellation of a document that already has a name, because that is an act a human could have been asked to approve. The custody stamp carries the act it was established for rather than a bare boolean, which is the state the vulnerable code lacked.
Upgrading changes behavior. Any ERPNext flow where a submit cascades into a lifecycle cancel now requires a consent marker for that cancel as well as for the act itself. In ERPNext v16 that includes asset sale, partial-quantity asset sale, a credit note against an asset sale, Asset Repair capitalization, Asset Shift Allocation, Asset Value Adjustment, and Unreconcile Payment. To make that possible, the X-Pacioli-Consent header now accepts several markers separated by whitespace or commas; each remains bound to one document and one act, requires a different minter, and is spent exactly once.
Workarounds
On 0.9.6, remove requireconsent from affected grants and rely on the credential-scoping floor alone, or scope governed credentials so they cannot submit documents whose controllers cancel other documents (for ERPNext slice-one, Sales Invoice with a populated item-row asset link is the known path). Neither is a substitute for upgrading.
Residual, stated
Under a governed cancel, a cascaded cancel of a pre-existing document still rides. That is load-bearing for undo (an ordinary invoice cancel makes ERPNext cancel the credit/debit notes and journals it generated, via accountscontroller.py:2001-2005) and cannot be narrowed without a signal that a cascaded cancel is a consequence of the enclosing document specifically. That justification does not describe everything the residual admits: at least one instance is caller-steered in the same shape as the issue fixed here, Asset Repair.oncancel (assetrepair.py:215-222), which cancels a Serial and Batch Bundle named by a Link the caller fills in a child table. pacioli-guard also does not see writes that set flags.ignorevalidate or that skip the document lifecycle entirely (raw SQL, dbupdate/dbset field writes); those residuals are published in the project's own documentation and are unchanged by this advisory.
Credit
Found by an internal adversarial review on 2026-07-28 that traced the predicate against frappe 16.28.0 and ERPNext v16 source rather than the project's own documentation. The prior code comment asserted that no such lever was known; that assertion had been written without the corresponding source sweep.
Other sources
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.requireconsent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pacioli-guardto a version that resolves this vulnerability.Fixed in 0.10.0 - Upgrade
Upgrade
pacioli-guardto a version that resolves this vulnerability.Fixed in 0.10.0 - Configuration
On version 0.9.6, remove require_consent from affected grants and rely on the credential-scoping floor alone.
pacioli-guard API Key Scope require_consent = disabled - Compensating control
Scope governed credentials so they cannot submit documents whose controllers cancel other documents; for the ERPNext slice-one path, prevent submission of Sales Invoice documents with a populated item-row asset link.
Event History
Frequently Asked Questions
Which deployments and principals are affected?
pacioli versions 0.9.6 through before 0.10.0 are affected. Only principals using a credential with API Key Scope.require_consent are exposed; principals without a consent-gated grant are not affected.
What does an attacker need to exploit this?
The attacker needs a credential with API Key Scope.require_consent and a valid human-minted submit marker. They can submit a caller-controlled supported document and use the nested operation to cancel a different pre-existing submitted document.
What is the impact of a successful exploit?
A successful exploit can invoke Document.cancel() on an unauthorized target document, bypassing the marker's document and act binding, single-use spend, and denial audit. Cancelling the target may reverse its ledger effect.
What is the remediation?
Upgrade pacioli to version 0.10.0, which fixes the issue.