CVE-2026-55242: ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ERPNextto a version that resolves this vulnerability.Fixed in 15.111.0 - Upgrade
Upgrade
ERPNextto a version that resolves this vulnerability.Fixed in 16.22.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55242?
The severity of CVE-2026-55242 is rated high with a score of 8.8.
How do I fix CVE-2026-55242?
To fix CVE-2026-55242, upgrade to ERPNext version 15.111.0 or 16.22.0 or higher.
What type of vulnerability is CVE-2026-55242?
CVE-2026-55242 is classified as a Server-Side Template Injection (SSTI) vulnerability.
Who can exploit CVE-2026-55242?
CVE-2026-55242 can be exploited by authenticated users with a standard operational role.
What data exposure risk does CVE-2026-55242 pose?
CVE-2026-55242 allows unauthorized disclosure of data outside the user's normal access.