What is CVE-2026-65822?
CVE-2026-65822 is an SQL injection vulnerability in the open-source ERP tool ERPNext, affecting authenticated users. The flaw exists in the 'Inactive Customers' report where an unvalidated 'doctype' filter is interpolated into raw SQL queries. Users should upgrade to versions 15.116.0, 16.23.0, or later.
Azərbaycanca: CVE-2026-65822: ERPNext açıq mənbəli ERP alətində autentifikasiya olunmuş istifadəçilər üçün SQL injection zəifliyidir. 'Inactive Customers' hesabatında doğrulanmamış 'doctype' filtri vasitəsilə xam SQL sorğusuna müdaxilə mümkündür. Təşkilatlar ERPNext-i 15.116.0 və ya 16.23.0 və daha yuxarı versiyalara yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Does exploiting CVE-2026-65822 require the attacker to be authenticated?
Yes, CVE-2026-65822 is an SQL injection vulnerability that can only be exploited by authenticated users.
In which ERPNext component does the CVE-2026-65822 vulnerability reside?
The vulnerability resides in the 'Inactive Customers' report, where an unvalidated 'doctype' filter is interpolated into raw SQL queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.