What is CVE-2026-72908?
An authenticated low-privilege user in ERPNext can perform SQL injection via the get_tax_template function in tax_rule.py due to improper sanitization of request-influenced posting_date and args values. This vulnerability affects versions prior to 15.109.0 and 16.20.0. Immediate update to the patched versions is required.
Azərbaycanca: ERPNext sistemində aşağı səlahiyyətli autentifikasiya olunmuş istifadəçi SQL injection hücumu həyata keçirə bilər. Bu zəiflik 'tax_rule.py' faylındakı 'get_tax_template' funksiyasında 'posting_date' və 'args' dəyərlərinin düzgün təmizlənməməsindən qaynaqlanır. Təcili olaraq 15.109.0 və ya 16.20.0 versiyalarına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which file and function does the SQL injection vulnerability exist in ERPNext?
The vulnerability exists in the `get_tax_template` function within the `tax_rule.py` file.
Which ERPNext versions are recommended for updating to fix CVE-2026-72908?
It is recommended to immediately update to versions 15.109.0 or 16.20.0 to fix this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.