What is CVE-2026-13227?
CVE-2026-13227 is an Improper Authorization vulnerability in ERPNext, caused by insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. It affects versions before 15.115.0 and 16.26.0, allowing unauthorized users to access sensitive data, and requires updating to the specified versions for mitigation.
Azərbaycanca: CVE-2026-13227 ERPNext platformasında "get_opportunities" API metodunda yetərsiz giriş nəzarəti səbəbindən "Improper Authorization" zəifliyidir. Bu boşluq 15.115.0 və 16.26.0 versiyalarından əvvəlki versiyalara təsir edir. İstismar zamanı icazəsiz istifadəçi həssas məlumatlara çıxış əldə edə bilər, təhlükəsizlik üçün sistemi göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which ERPNext method was the CVE-2026-13227 vulnerability discovered?
The vulnerability arises from insufficient access control in the whitelisted API method called get_opportunities within ERPNext's CRM module.
Which ERPNext versions should be updated to protect against the CVE-2026-13227 Improper Authorization vulnerability?
To mitigate this vulnerability, it is recommended to update the system to ERPNext versions 15.115.0 or 16.26.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.