CVE-2026-72909 | Frappe ERPNext up to 15.111.x/16.22.x ReceivablePayableReport accounts_receivable.py prepare_conditions permission
A vulnerability classified as problematic was found in Frappe ERPNext up to 15.111.x/16.22.x. This affects the function prepare_conditions of the file erpnext/accounts/report/accounts_receivable/accounts_receivable.py of the component ReceivablePayableReport. The manipulation results in permission issues.
This vulnerability is reported as CVE-2026-72909. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More