CVE-2026-44441: ERPNext: Possible SSRF by any authenticated user
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16.16.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44441?
CVE-2026-44441 has a high severity rating due to its potential for Server-Side Request Forgery (SSRF) vulnerabilities.
How do I fix CVE-2026-44441?
To fix CVE-2026-44441, upgrade ERPNext to versions 15.106.0 or 16.16.0 or later.
Who is affected by CVE-2026-44441?
CVE-2026-44441 affects users of ERPNext versions prior to 15.106.0 and 16.16.0.
What type of vulnerability is CVE-2026-44441?
CVE-2026-44441 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Can an unauthenticated user exploit CVE-2026-44441?
No, CVE-2026-44441 can only be exploited by authenticated users of the ERPNext application.