MEDIUMVulnerability

CVE-2026-72907

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master records and affect financial data integrity and audit trails. This issue is fixed in versions 15.111.0 and 16.22.0.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00246
cve_id
CVE-2026-72907
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-10T21:17:25.460
last_modified
2026-09-08T20:54:37.790
epss_percentile
0.15845

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72907 — Ninja Signal Threat Intelligence | Ninja Signal