CVE-2026-72906
Received Received - Intake

Permission Bypass in ERPNext Auto-Email Function

Vulnerability report for CVE-2026-72906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: GitHub, Inc.

Description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege user to trigger automated emails outside the permitted role. This issue is fixed in versions 15.111.0 and 16.22.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
erpnext erpnext to 16.22.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ERPNext allows an authenticated low-privilege user to trigger automated emails without proper permission checks. The send_auto_email function in the Process Statement Of Accounts module lacks a required permission check, enabling unauthorized email triggers.

Impact Analysis

An attacker could exploit this to send bulk emails, potentially spamming users or leaking sensitive information. This could disrupt operations, waste resources, or lead to phishing risks if emails appear legitimate but are unauthorized.

Compliance Impact

This vulnerability could violate compliance by enabling unauthorized data processing or communication. GDPR may require consent for automated emails, while HIPAA mandates strict access controls for sensitive health data. Unauthorized emails may breach these requirements.

Mitigation Strategies

Upgrade ERPNext to version 15.111.0 or later for the 15.x branch, or to version 16.22.0 or later for the 16.x branch. This will patch the missing permission check in the send_auto_email function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72906. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart