PT-2026-109294 · Pacioli · Pacioli

CVE-2026-107841

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions pacioli versions 0.9.6 through 0.9.6
Description The pacioli-guard document-layer consent gate allows nested cancellation operations to bypass authorization checks by riding the consent established by an enclosing governed act. A credential with API Key Scope.require consent can submit a caller-controlled document, such as a Sales Invoice, using a valid human-minted submit marker to trigger the Document.cancel() function for a different, pre-existing submitted document. This bypasses the marker's document and act binding, single-use spend, and denial audit, potentially reversing the target document's ledger effect. This occurs because the ride predicate returned true for every cancel operation regardless of the act the enclosing marker authorized, skipping the consent verdict where marker-to-act binding is enforced. Examples of affected flows include Sales Invoice.on submit calling process asset depreciation() and Unreconcile Payment.on submit calling gain loss je.cancel().
Recommendations Update pacioli to version 0.10.0. As a temporary workaround, remove require consent from affected grants and rely on the credential-scoping floor, or scope governed credentials to prevent the submission of documents whose controllers cancel other documents.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107841
GHSA-3HJ7-6VMJ-H8V4

Affected Products

Pacioli