CVE-2026-44442: ERPNext: Unauthorised Document modification due to missing validation
Published May 13, 2026
·Updated
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.
Affected Software
2 affected components
Frappe ERPNext<16.9.1
Frappe ERPNext<16.9.1
Event History
May 13, 2026
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44442?
CVE-2026-44442 is classified as a high severity vulnerability due to unauthorized document modification capabilities.
2
How do I fix CVE-2026-44442?
To fix CVE-2026-44442, you should upgrade your ERPNext installation to version 16.9.1 or later.
3
What are the consequences of CVE-2026-44442 if left unpatched?
If left unpatched, CVE-2026-44442 can allow unauthorized users to modify important business documents and data.
4
Which versions of ERPNext are affected by CVE-2026-44442?
CVE-2026-44442 affects all versions of ERPNext prior to 16.9.1.
5
What type of vulnerability is CVE-2026-44442?
CVE-2026-44442 is an authorization-related vulnerability that permits improper document modification.