← Vulnerability feed

Vulnerability record · CVE-2026-44442 · published 13 May 2026

CVE-2026-44442: Frappe erpnext missing authorization vulnerability

Frappe · Erpnext

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

9.9 CVSS 3.1 Critical EPSS 0.42% · top 66.5% CWE-862 · Missing authorization
9.9CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-38431Frappe erpnext code injection vulnerabilityERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…EPSS 0.60%9.6CVE-2025-67289Frappe erpnext cross-site scripting vulnerabilityAn arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…EPSS 0.46%9.3CVE-2026-27471Frappe erpnext improper access control vulnerabilityERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…EPSS 0.44%9.1CVE-2026-31017Frappe erpnext server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…EPSS 0.42%9.1CVE-2025-58439Frappe erpnext sql injection vulnerabilityERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of paramete…EPSS 0.32%9.0CVE-2025-65267Frappe erpnext cross-site scripting vulnerabilityIn ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …EPSS 0.35%8.8CVE-2025-66437Frappe erpnext code injection vulnerabilityAn SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend…EPSS 0.60%8.8CVE-2025-66438Frappe erpnext code injection vulnerabilityA Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2026-44442), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.