← לוח פגיעויות

CVE-2026-44442

קריטית 9.9

תיאור (מקור, אנגלית)

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

מדדים

CVSS 3.1
9.9 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-30/9/2026
CWE
CWE-862

מוצרים מושפעים

frappe: erpnext

קישורים