What is CVE-2026-72909?
CVE-2026-72909 is a vulnerability in the open-source ERPNext tool, affecting versions prior to 15.112.0 and 16.23.0. It fails to apply Customer and Supplier user permissions to the Payment Ledger in the ReceivablePayableReport prepare_conditions path. Update to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-72909, ERPNext açıq mənbəli ERP alətində aşkarlanmış zəiflikdir. Versiya 15.112.0 və 16.23.0-dən əvvəlki versiyalarda 'ReceivablePayableReport prepare_conditions' funksiyası 'Customer' və 'Supplier' istifadəçi icazələrini 'Payment Ledger'ə tətbiq etmir. Təhlükəsizlik üçün ən son versiyaya yeniləməlisiniz.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which product is affected by CVE-2026-72909?
This vulnerability affects the open-source ERPNext ERP tool.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.