SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-55242

HIGH · CVSS 8.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Authenticated users with standard operational roles in ERPNext prior to versions 15.111.0 and 16.22.0 can exploit a server-side template injection vulnerability via a configuration field, leading to unauthorized data disclosure beyond their permissions. Organizations using affected versions should prioritize upgrading to the patched releases to mitigate the risk of sensitive data exposure. This vulnerability poses a significant threat to data integrity and confidentiality, making it critical for all ERPNext users to address promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55242
Severity
HIGH
CVSS
8.8
EPSS
0.14%

Original NVD Description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.