CVE-2026-44441: Frappe Erpnext

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16.16.0.

Affected products

  • Frappe Erpnext: before 15.106.0 (fixed in 15.106.0); from 16.0.0, before 16.16.0 (fixed in 16.16.0)

Published 2026-05-13. Last modified 2026-06-17.