CVE-2026-44446: ERPNext: Possibility of SQL Injection due to missing validation
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16.14.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44446?
CVE-2026-44446 is classified as a high severity vulnerability due to the potential for SQL injection, allowing unauthorized access to sensitive data.
How do I fix CVE-2026-44446?
To fix CVE-2026-44446, update ERPNext to version 15.104.3 or later for the 15.x branch, or 16.14.0 or later for the 16.x branch.
Who is affected by CVE-2026-44446?
CVE-2026-44446 affects users of ERPNext versions prior to 15.104.3 and 16.14.0.
What type of vulnerability is CVE-2026-44446?
CVE-2026-44446 is a SQL Injection vulnerability, which occurs due to missing validation in certain endpoints.
What can attackers do with CVE-2026-44446?
Attackers can exploit CVE-2026-44446 to execute SQL queries that could lead to the extraction of sensitive information from the database.