CVE-2026-107841: John-Broadway Pacioli

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.

Affected products

  • John-Broadway Pacioli: from 0.9.6, before 0.10.0 (fixed in 0.10.0)

Published 2026-10-09. Last modified 2026-10-09.