CVE-2026-72907 | Frappe ERPNext up to 15.110.x/16.21.x utils.py add_ac ignore_permissions privileges management

SecurityVulns

A vulnerability classified as problematic was found in Frappe ERPNext up to 15.110.x/16.21.x. Affected by this vulnerability is the function add_ac of the file erpnext/accounts/utils.py. Such manipulation of the argument ignore_permissions leads to improper privilege management.

This vulnerability is documented as CVE-2026-72907. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More