CVE-2026-44440: ERPNext: Path Traversal Leading to Sensitive File Exposure
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnerability is fixed in 15.101.1 and 16.10.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44440?
CVE-2026-44440 is classified as a medium severity vulnerability due to its potential for sensitive file exposure.
How do I fix CVE-2026-44440?
To mitigate CVE-2026-44440, upgrade ERPNext to version 15.101.1 or 16.10.0 or later.
What does CVE-2026-44440 affect?
CVE-2026-44440 affects Frappe ERPNext prior to versions 15.101.1 and 16.10.0.
What type of vulnerability is CVE-2026-44440?
CVE-2026-44440 is a Path Traversal vulnerability that can lead to sensitive file exposure.
Who is impacted by CVE-2026-44440?
Anyone using affected versions of ERPNext prior to 15.101.1 or 16.10.0 is impacted by CVE-2026-44440.