← Vulnerability feed

Vulnerability record · CVE-2026-27471 · published 21 February 2026

CVE-2026-27471: Frappe erpnext improper access control vulnerability

Frappe · Erpnext

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

9.3 CVSS 4.0 Critical EPSS 0.44% · top 64.5% CWE-284 · Improper access controlCWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27471 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-44442Frappe erpnext missing authorization vulnerabilityERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks…EPSS 0.42%9.8CVE-2026-38431Frappe erpnext code injection vulnerabilityERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…EPSS 0.60%9.6CVE-2025-67289Frappe erpnext cross-site scripting vulnerabilityAn arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…EPSS 0.46%9.1CVE-2026-31017Frappe erpnext server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…EPSS 0.42%9.1CVE-2025-58439Frappe erpnext sql injection vulnerabilityERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of paramete…EPSS 0.32%9.0CVE-2025-65267Frappe erpnext cross-site scripting vulnerabilityIn ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …EPSS 0.35%8.8CVE-2025-66437Frappe erpnext code injection vulnerabilityAn SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend…EPSS 0.60%8.8CVE-2025-66438Frappe erpnext code injection vulnerabilityA Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2026-27471), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.