CVE-2026-27471

CRITICAL WAF: Low
CVSS 9.1 Published: 2026-02-21
CWE-862

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

WAF Coverage Analysis

Missing Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
frappeerpnextup to 15.98.1
frappeerpnextup to 16.6.1
frappeerpnext16.0.0
frappeerpnext16.0.0
frappeerpnext16.0.0

References

Back to CVE Database