CVE-2026-27471: Frappe Erpnext
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Affected products
- Frappe Erpnext: before 15.98.1 (fixed in 15.98.1); after 16.0.0, before 16.6.1 (fixed in 16.6.1); version 16.0.0 only
Published 2026-02-21. Last modified 2026-06-17.