CVE-2026-27471: ERP: Document access through endpoints due to missing validation
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27471?
The severity of CVE-2026-27471 is classified as high due to unauthorized access to sensitive documents.
How do I fix CVE-2026-27471?
To fix CVE-2026-27471, ensure to update the ERP software to version 16.6.1 or later which includes necessary access validations.
What are the affected versions in CVE-2026-27471?
CVE-2026-27471 affects ERP versions up to 15.98.0 and versions between 16.0.0-rc.1 through 16.6.0.
What type of vulnerability is CVE-2026-27471?
CVE-2026-27471 is an access control vulnerability allowing unauthorized access to documents.
Can CVE-2026-27471 be exploited remotely?
Yes, CVE-2026-27471 can be exploited remotely if the vulnerable software is accessible over the network.