What is CVE-2026-72906?
CVE-2026-72906 affects ERPNext, an open-source ERP tool, where the 'send_auto_email' function in versions prior to 15.111.0 and 16.22.0 lacks permission checks. This allows an authenticated user to perform unauthorized actions. Upgrading to the latest versions is recommended.
Azərbaycanca: CVE-2026-72906, ERPNext açıq mənbəli ERP alətində aşkarlanmışdır. 15.111.0 və 16.22.0 versiyalarından əvvəlki versiyalarda 'send_auto_email' funksiyasında icazə yoxlanışının olmaması səbəbindən autentifikasiya olunmuş istifadəçi icazəsiz əməliyyatlar həyata keçirə bilər. Sisteminizi göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which function was CVE-2026-72906 detected in ERPNext?
The vulnerability occurs due to missing permission checks in the 'send_auto_email' function.
Which versions should you upgrade to in order to mitigate CVE-2026-72906?
It is recommended to upgrade ERPNext to versions 15.111.0 and 16.22.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.