CVE-2026-72906 | Frappe ERPNext up to 15.110.x/16.21.x Process Statement Of Accounts process_statement_of_accounts.py send_auto_email privileges management
A vulnerability classified as critical has been found in Frappe ERPNext up to 15.110.x/16.21.x. Affected is the function send_auto_email of the file erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py of the component Process Statement Of Accounts. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2026-72906. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More