CVE-2026-44447: ERPNext: Possibility of SQL Injection due to missing validation
Published May 13, 2026
·Updated
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.
Affected Software
2 affected components
Frappe ERPNext<16.9.0
Frappe ERPNext<16.9.0
Event History
May 13, 2026
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44447?
CVE-2026-44447 is a critical severity vulnerability that allows for SQL injection.
2
How do I fix CVE-2026-44447?
To fix CVE-2026-44447, update ERPNext to version 16.9.0 or later.
3
What types of systems are affected by CVE-2026-44447?
CVE-2026-44447 affects Frappe ERPNext versions prior to 16.9.0.
4
What can attackers do with CVE-2026-44447?
Attackers can exploit CVE-2026-44447 to execute arbitrary SQL queries, potentially extracting sensitive information.
5
Is CVE-2026-44447 patched in the latest versions?
Yes, CVE-2026-44447 has been patched in ERPNext version 16.9.0.