CVE-2026-44448: ERPNext: Unauthorised Document modification due to missing validation
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44448?
CVE-2026-44448 is categorized as a high severity vulnerability due to unauthorized document modification risks.
How do I fix CVE-2026-44448?
To fix CVE-2026-44448, upgrade ERPNext to version 15.102.0 or 16.11.0 or later where the vulnerability is addressed.
Who is affected by CVE-2026-44448?
CVE-2026-44448 affects users of ERPNext versions prior to 15.102.0 and 16.11.0.
What types of modifications are possible due to CVE-2026-44448?
CVE-2026-44448 allows unauthorized users to modify data that exceeds their permitted role.
What system components are impacted by CVE-2026-44448?
CVE-2026-44448 specifically impacts certain endpoints within the ERPNext application that do not enforce proper authorization checks.