PT-2026-109294 · Pacioli · Pacioli
CVE-2026-107841
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pacioli versions 0.9.6 through 0.9.6
Description
The
pacioli-guard document-layer consent gate allows nested cancellation operations to bypass authorization checks by riding the consent established by an enclosing governed act. A credential with API Key Scope.require consent can submit a caller-controlled document, such as a Sales Invoice, using a valid human-minted submit marker to trigger the Document.cancel() function for a different, pre-existing submitted document. This bypasses the marker's document and act binding, single-use spend, and denial audit, potentially reversing the target document's ledger effect. This occurs because the ride predicate returned true for every cancel operation regardless of the act the enclosing marker authorized, skipping the consent verdict where marker-to-act binding is enforced. Examples of affected flows include Sales Invoice.on submit calling process asset depreciation() and Unreconcile Payment.on submit calling gain loss je.cancel().Recommendations
Update pacioli to version 0.10.0.
As a temporary workaround, remove
require consent from affected grants and rely on the credential-scoping floor, or scope governed credentials to prevent the submission of documents whose controllers cancel other documents.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pacioli