CVE-2026-72911: ERPNext: Possibility of server-side template injection due to missing validation
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validatetemplate and rendertemplate calls in erpnext/accounts/doctype/processstatementofaccounts/processstatementofaccounts.py render subject, body, and pdfname fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inject template expressions, execute arbitrary server-side code, and read data across the application. This issue is fixed in versions 15.118.0 and 16.29.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ERPNextto a version that resolves this vulnerability.Fixed in 15.118.0 - Upgrade
Upgrade
ERPNextto a version that resolves this vulnerability.Fixed in 16.29.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72911?
The severity of CVE-2026-72911 is critical with a score of 9.9.
How does CVE-2026-72911 impact ERPNext?
CVE-2026-72911 allows for server-side template injection due to missing validation in ERPNext.
How do I fix CVE-2026-72911?
To fix CVE-2026-72911, upgrade to ERPNext version 15.118.0 or 16.29.0 or later.
What systems are affected by CVE-2026-72911?
CVE-2026-72911 affects ERPNext versions prior to 15.118.0 and 16.29.0.
What are the consequences of exploiting CVE-2026-72911?
Exploiting CVE-2026-72911 could lead to significant data loss and unauthorized access to sensitive information.