What is CVE-2026-65974?
This vulnerability affects ERPNext versions prior to 15.111.0 and 16.22.0. Limited authenticated users can bypass permission boundaries due to `frappe.render_template` being exposed without enforcing `restrict_globals`, leading to server-side template injection (SSTI). Immediate update to the patched versions is required for mitigation.
Azərbaycanca: Bu boşluq ERPNext açıq mənbəli ERP alətinin 15.111.0 və 16.22.0-dən əvvəlki versiyalarına təsir edir. Məhdud autentifikasiyalı istifadəçilər `frappe.render_template` funksiyası vasitəsilə `restrict_globals` məcburi edilmədiyi üçün server-side template injection (SSTI) həyata keçirə bilərlər. Təhlükəsizlik üçün sistem dərhal göstərilən versiyalara yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which ERPNext versions are affected by CVE-2026-65974?
This vulnerability affects ERPNext versions prior to 15.111.0 and prior to 16.22.0.
How to mitigate CVE-2026-65974 vulnerability?
An immediate update to the patched versions (15.111.0 or 16.22.0) is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.