PT-2026-97358 · Frappe · Erpnext

·

CVE-2026-96672

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe ERPNext versions prior to 16.34.1
Description Accounts Managers can invoke non-whitelisted internal server-side methods and read their return values. This occurs because the software fails to validate that the calculation formula values within the Financial Report Template reference whitelisted methods before they are passed to the frappe.call() function. An attacker can supply arbitrary dotted Python paths to execute these unauthorized methods.
Recommendations Update to version 16.34.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96672
GHSA-794X-FHM7-58J7

Affected Products

Erpnext