CVE-2026-72910 | Frappe ErpNext up to 15.111.x/16.21.x Accounts account.py permission
A vulnerability categorized as problematic has been discovered in Frappe ErpNext up to 15.111.x/16.21.x. This affects the function merge_account/pause_job_for_doc/trigger_job_for_doc/change_release_date/update_cost_center of the file erpnext/accounts/doctype/account/account.py of the component Accounts. The manipulation results in permission issues.
This vulnerability is identified as CVE-2026-72910. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More