What is CVE-2026-72907?
CVE-2026-72907 affects ERPNext versions prior to 15.111.0 and 16.22.0, where the `add_ac` function fails to properly enforce 'Account create permission'. This allows an authenticated limited user to create unauthorized accounts by exploiting the `ignore_permissions` argument. Users are advised to update to the patched versions immediately.
Azərbaycanca: CVE-2026-72907, ERPNext-in 15.111.0 və 16.22.0-dan əvvəlki versiyalarında `add_ac` funksiyasında icazə yoxlamasının düzgün aparılmaması ilə bağlıdır. Bu zəiflik autentifikasiya olunmuş, lakin məhdud icazəli istifadəçiyə icazəsiz Account yaratmağa imkan verir. İstifadəçilərə ən son təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What software is affected by CVE-2026-72907?
CVE-2026-72907 affects ERPNext versions prior to 15.111.0 and 16.22.0.
What can an authenticated limited user do by exploiting CVE-2026-72907?
This vulnerability allows an authenticated limited user to create unauthorized accounts by exploiting the `ignore_permissions` argument in the `add_ac` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.