CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72911

criticalCVSS 9.9covered by 1 sourcefirst seen 2026-08-10
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inject template expressions, execute arbitrary server-side code, and read data across the application. This issue is fixed in versions 15.118.0 and 16.29.0.

⚡ Watch CVE-2026-72911

Get an email if CVE-2026-72911 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-72911

CVE.org record

Embed the live status

CVE-2026-72911 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72911 status](https://www.csirts.com/badge/CVE-2026-72911)](https://www.csirts.com/cve/CVE-2026-72911)